Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Mozilla Firefox Multiple Vulnerabilities - July12 (Mac OS X)
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is installed with Mozilla firefox and is prone to multiple vulnerabilities.
Insight
Insight
- The improper implementation of drag-and-drop feature, fails to display the URL properly in addressbar. - An error when handling 'feed:' URLs can be exploited to bypass the output filters and execute arbitrary JavaScript code. - The context-menu restrictions for data: URLs are not the same as for javascript: URLs, which allows to conduct XSS attacks.
Affected Software
Affected Software
Mozilla Firefox version 4.x through 13.0 Mozilla Firefox ESR version 10.x before 10.0.6 on Mac OS X
Solution
Solution
Upgrade to Mozilla Firefox version 14.0 or ESR version 10.0.6 or later.
Common Vulnerabilities and Exposures (CVE)
References
- http://secunia.com/advisories/49965
- http://securitytracker.com/id/1027256
- http://securitytracker.com/id/1027257
- http://www.mozilla.org/security/announce/2012/mfsa2012-43.html
- http://www.mozilla.org/security/announce/2012/mfsa2012-46.html
- http://www.mozilla.org/security/announce/2012/mfsa2012-55.html
- http://www.mozilla.com/en-US/firefox/all.html