Free and open-source vulnerability scanner
Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.
Install NowAvailable for macOS, Windows, and Linux
Mozilla Firefox Security Updates( mfsa_2017-18_2017-19 )-MAC OS X
Information
Severity
Severity
Family
Family
CVSSv2 Base
CVSSv2 Base
CVSSv2 Vector
CVSSv2 Vector
Solution Type
Solution Type
Created
Created
Modified
Modified
Summary
This host is installed with Mozilla Firefox and is prone to multiple vulnerabilities.
Insight
Insight
The multiple flaws exists due to, - XUL injection in the style editor in devtools. - Use-after-free in WebSockets during disconnection. - Use-after-free with marquee during window resizing. - Use-after-free while deleting attached editor DOM node. - Use-after-free with image observers. - Use-after-free resizing image elements. - Buffer overflow manipulating ARIA attributes in DOM. - Buffer overflow while painting non-displayable SVG. - Use-after-free in layer manager with SVG. - Out-of-bounds read with cached style data and pseudo-elements. - Same-origin policy bypass with iframes through page reloads. - Domain hijacking through AppCache fallback. - Buffer overflow viewing certificates with an extremely long OID. - Spoofing following page navigation with data: protocol and modal alerts. - CSP information leak with frame-ancestors containing paths. - Elliptic curve point addition error when using mixed Jacobian-affine coordinates. - CSP containing sandbox improperly applied. - Self-XSS XUL injection in about:webrtc. - DOS attack through long username in URL. - Sandboxed about:srcdoc iframes do not inherit CSP directives. - Failure to enable HSTS when two STS headers are sent for a connection. - Response header name interning leaks across origins. - Memory safety bugs.
Affected Software
Affected Software
Mozilla Firefox version before 55.0 on MAC OS X.
Detection Method
Detection Method
Checks if a vulnerable version is present on the target host.
Solution
Solution
Upgrade to Mozilla Firefox version 55.0 or later.
Common Vulnerabilities and Exposures (CVE)
- CVE-2017-7798
- CVE-2017-7800
- CVE-2017-7801
- CVE-2017-7809
- CVE-2017-7784
- CVE-2017-7802
- CVE-2017-7785
- CVE-2017-7786
- CVE-2017-7806
- CVE-2017-7753
- CVE-2017-7787
- CVE-2017-7807
- CVE-2017-7792
- CVE-2017-7791
- CVE-2017-7808
- CVE-2017-7779
- CVE-2017-7781
- CVE-2017-7803
- CVE-2017-7799
- CVE-2017-7783
- CVE-2017-7788
- CVE-2017-7789
- CVE-2017-7797
- CVE-2017-7780