Browser Security News

The Site for Web Browser Security Information

Welcome to Browser Security News

Because Web Browser Security Matters!

 

Your news resource for Internet Explorer, Firefox, Opera and Safari security news vulnerabilities, virus and other important information.

Categories

Archives

Feeds

CVE-2008-3623 (safari)

Heap-based buffer overflow in CoreGraphics in Apple Safari before 3.2 on Windows allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted image, related to improper handling of color spaces.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 17th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-3644 (safari)

Apple Safari before 3.2 does not properly prevent caching of form data for form fields that have autocomplete disabled, which allows local users to obtain sensitive information by reading the browser’s page cache.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 17th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-4216 (safari)

The plug-in interface in WebKit in Apple Safari before 3.2 does not prevent plug-ins from accessing local URLs, which allows remote attackers to obtain sensitive information via vectors that “launch local files.”

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 17th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-0017 (firefox, seamonkey)

The http-index-format MIME type parser (nsDirIndexParser) in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 does not check for an allocation failure, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an HTTP index response with a crafted 200 header, which triggers memory corruption and a buffer overflow.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 13th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-5012 (firefox, seamonkey, thunderbird)

Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly change the source URI when processing a canvas element and an HTTP redirect, which allows remote attackers to bypass the same origin policy and access arbitrary images that are not directly accessible to the attacker. NOTE: this issue can be leveraged to enumerate software on the client by performing redirections related to moz-icon.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 13th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-5013 (firefox, seamonkey)

Mozilla Firefox 2.x before 2.0.0.18 and SeaMonkey 1.x before 1.1.13 do not properly check when the Flash module has been dynamically unloaded properly, which allows remote attackers to execute arbitrary code via a crafted SWF file that “dynamically unloads itself from an outside JavaScript function,” which triggers an access of an expired memory address.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 13th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-5014 (firefox, seamonkey, thunderbird)

jslock.cpp in Mozilla Firefox 3.x before 3.0.2, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying the window.__proto__.__proto__ object in a way that causes a lock on a non-native object, which triggers an assertion failure related to the OBJ_IS_NATIVE function.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 13th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-5015 (firefox)

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 13th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-5016 (firefox, seamonkey, thunderbird)

The layout engine in Mozilla Firefox 3.x before 3.0.4, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via multiple vectors that trigger an assertion failure or other consequences.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 13th, 2008 in Latest News, National Vulnerability Db | No Comments »

CVE-2008-5017 (firefox, seamonkey, thunderbird)

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.

Read More…
Source: National Vulnerability Database

The Hackers’ Nightmare is here!

Posted on November 13th, 2008 in Latest News, National Vulnerability Db | No Comments »

« Previous Entries