Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Mozilla Firefox Multiple Vulnerabilities - Aug15 (Mac OS X)

Information

Severity

Severity

Critical

Family

Family

General

CVSSv2 Base

CVSSv2 Base

10.0

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

Solution Type

Solution Type

Vendor Patch

Created

Created

8 years ago

Modified

Modified

5 years ago

Summary

This host is installed with Mozilla Firefox and is prone to multiple vulnerabilities.

Insight

Insight

Multiple flaws exists due to, - The 'mozilla::AudioSink' function in Mozilla Firefox mishandles inconsistent sample formats within MP3 audio data. - Use-after-free vulnerability in the MediaStream playback feature. - Not imposing certain ECMAScript 6 requirements on JavaScript object properties. - Multiple integer overflows in libstagefright. - Vulnerability in 'mar_read.c' script in the Updater. - Vulnerability in 'js::jit::AssemblerX86Shared::lock_addl' function in the JavaScript implementation. - Heap-based buffer overflow in the 'resize_context_buffers' function in libvpx. - Vulnerability in decrease_ref_count function in libvpx. - Overflow vulnerability in 'nsTSubstring::ReplacePrep' function. - Use-after-free vulnerability in the 'StyleAnimationValue' class. - Vulnerability in 'nsTArray_Impl' class in Mozilla Firefox. - Improper implementation of Content Security Policy by 'nsCSPHostSrc::permits' function in 'dom/security/nsCSPUtils.cpp' script. - Use-after-free vulnerability in the 'XMLHttpRequest::Open' implementation. - Heap-based buffer overflow in the 'stagefright::ESDS::parseESDescriptor' function in libstagefright. - Multiple unspecified vulnerabilities.

Affected Software

Affected Software

Mozilla Firefox version before 40.0 on Mac OS X

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Upgrade to Mozilla Firefox version 40.0 or later.