Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Mozilla Firefox Multiple Memory Corruption Vulnerabilities Aug-09 (Windows)

Information

Severity

Severity

Critical

Family

Family

General

CVSSv2 Base

CVSSv2 Base

10.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

14 years ago

Modified

Modified

5 years ago

Summary

This host is installed with Mozilla Firefox and is prone to multiple Memory Corruption vulnerabilities.

Insight

Insight

Multiple memory corruption are due to: - Error in 'js_watch_set()' function in js/src/jsdbgapi.cpp in the JavaScript engine which can be exploited via a crafted '.js' file. - Error in 'libvorbis()' which is used in the application can be exploited via a crafted '.ogg' file. - Error in 'TraceRecorder::snapshot()' function in js/src/jstracer.cpp and other unspecified vectors. - Error in 'window.open()' which fails to sanitise the invalid character in the crafted URL. This allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

Affected Software

Affected Software

Firefox version before 3.0.13 or 3.5 before 3.5.2 on Windows.

Solution

Solution

Upgrade to Firefox version 3.0.13/3.5.2.

Common Vulnerabilities and Exposures (CVE)