Q-214: Mozilla Vulnerabilities
March 22nd, 2007 by NewsThere are multiple security vulnerabilties with Mozilla:
1) A buffer overflow in the crypto.signText() method;
2) A privilege excalation vulnerability exists in the Mozilla addSelectionListener method;
3) Mozilla allows content-defined setters on object prototypes;
4) Mozilla can allow persisted XUL attributes to associate with the wrong URL; and
5) Mozilla contains several memory corruption vulnerabilities.
The risk is Low. May allow a remote attacker to execute arbitrary code.
Read More…
Source: CIAC
Leave a Comment