Free and open-source vulnerability scanner

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

Mozilla Firefox Security Updates(mfsa_2018-06_2018-07)-MAC OS X

Information

Severity

Severity

High

Family

Family

General

CVSSv2 Base

CVSSv2 Base

7.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

6 years ago

Modified

Modified

5 years ago

Summary

This host is installed with Mozilla Firefox and is prone to multiple vulnerabilities.

Insight

Insight

Multiple flaws exists due to, - A buffer overflow error when manipulating SVG animatedPathSegList through script. - An use-after-free error during editor operations. - A lack of parameter validation on IPC messages. - A memory corruption error when packets with a mismatched RTP payload type are sent in WebRTC connections. - Fetch API improperly returns cached copies of no-store/no-cache resources. - The Find API for WebExtensions can search some privileged pages. - The value of the app.support.baseURL preference is not properly sanitized. - WebExtensions may use view-source: URLs to bypass content restrictions. - WebExtensions can bypass normal restrictions in some circumstances. - Same-origin policy violation with data: URL shared workers. - Script content can access legacy extension non-contentaccessible resources. - Moz-icon images accessible to web content through moz-icon: protocol. - A vulnerability in the notifications Push API. - Media Capture and Streams API permissions display incorrect origin with data: and blob: URLs. - Self-XSS pasting javascript: URL with embedded tab into addressbar. - Memory safety bugs fixed in Firefox 59.

Affected Software

Affected Software

Mozilla Firefox version before 59 on MAC OS X.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Upgrade to Mozilla Firefox version 59 or later.