|
|
|
Firefox Multiple Vulnerabilities
|
|
Secunia Advisory:
|
SA19631
|
|
|
Release Date:
|
2006-04-14
|
|
Last Update:
|
2006-06-07
|
|
Popularity:
|
85,956 views
|
|
|
Critical:
|
 Highly critical
|
|
Impact:
|
Security Bypass Cross Site Scripting Spoofing Exposure of sensitive information DoS System access
|
|
Where:
|
From remote
|
|
Solution Status:
|
Vendor Patch
|
|
| Software: | Mozilla Firefox 0.x Mozilla Firefox 1.x
|
|
|
Secunia CVSS-2 Score:
|
Available in Secunia business solutions
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| Advisory Content (Page 2 of 3) | [ 1 ] [ 2 ] [ 3 ] | |
|
Solution: Update to versions 1.0.8 or 1.5.0.2.
http://www.mozilla.com/firefox/
17) Update to version 1.5.0.4.
http://www.mozilla.com/firefox/
Provided and/or discovered by: 1, 9, 10, 12, 18, 20) shutdown
2) Igor Bukanov
3) Bernd Mielke
4) Alden D'Souza
5) Martijn Wargers
6) Bob Clary
7) Tristor
8) Michael Krax
11, 14, 21) moz_bug_r_a4
13, 16, 22) Discovered by anonymous and reported via TippingPoint and the Zero Day Initiative.
17) Claus Jørgensen and Jesse Ruderman
Additional information provided by Chuck McAuley.
19) Georgi Guninski
Changelog: 2006-04-17: Added information provided by TippingPoint and the Zero Day Initiative.
2006-04-18: Added links to US-CERT vulnerability notes.
2006-04-19: Added CVE reference.
2006-04-24: Vendor releases information about additional vulnerability. Added vulnerability #22 and CVE reference.
2006-04-26: Added information provided by TippingPoint and the Zero Day Initiative.
2006-06-02: New version released. Added information about that the added security check in #17 can be bypassed. Updated "Description" and "Solution" sections.
2006-06-07: Added CVE reference.
Original Advisory: Mozilla:
http://www.mozilla.org/security/announce/2006/mfsa2006-09.html
http://www.mozilla.org/security/announce/2006/mfsa2006-10.html
http://www.mozilla.org/security/announce/2006/mfsa2006-11.html
http://www.mozilla.org/security/announce/2006/mfsa2006-12.html
http://www.mozilla.org/security/announce/2006/mfsa2006-13.html
http://www.mozilla.org/security/announce/2006/mfsa2006-14.html
http://www.mozilla.org/security/announce/2006/mfsa2006-15.html
http://www.mozilla.org/security/announce/2006/mfsa2006-16.html
http://www.mozilla.org/security/announce/2006/mfsa2006-17.html
http://www.mozilla.org/security/announce/2006/mfsa2006-18.html
http://www.mozilla.org/security/announce/2006/mfsa2006-19.html
http://www.mozilla.org/security/announce/2006/mfsa2006-20.html
http://www.mozilla.org/security/announce/2006/mfsa2006-22.html
http://www.mozilla.org/security/announce/2006/mfsa2006-23.html
http://www.mozilla.org/security/announce/2006/mfsa2006-24.html
http://www.mozilla.org/security/announce/2006/mfsa2006-25.html
http://www.mozilla.org/security/announce/2006/mfsa2006-27.html
http://www.mozilla.org/security/announce/2006/mfsa2006-28.html
http://www.mozilla.org/security/announce/2006/mfsa2006-29.html
http://www.mozilla.org/security/announce/2006/mfsa2006-41.html
TippingPoint and the Zero Day Initiative:
http://www.zerodayinitiative.com/advisories/ZDI-06-009.html
http://www.zerodayinitiative.com/advisories/ZDI-06-010.html
http://www.zerodayinitiative.com/advisories/ZDI-06-011.html
Other References: US-CERT VU#179014:
http://www.kb.cert.org/vuls/id/179014
US-CERT VU#252324:
http://www.kb.cert.org/vuls/id/252324
US-CERT VU#329500:
http://www.kb.cert.org/vuls/id/329500
US-CERT VU#350262:
http://www.kb.cert.org/vuls/id/350262
US-CERT VU#488774:
http://www.kb.cert.org/vuls/id/488774
US-CERT VU#492382:
http://www.kb.cert.org/vuls/id/492382
US-CERT VU#736934:
http://www.kb.cert.org/vuls/id/736934
US-CERT VU#813230:
http://www.kb.cert.org/vuls/id/813230
US-CERT VU#842094:
http://www.kb.cert.org/vuls/id/842094
US-CERT VU#932734:
http://www.kb.cert.org/vuls/id/932734
US-CERT VU#935556:
http://www.kb.cert.org/vuls/id/935556
US-CERT VU#968814:
http://www.kb.cert.org/vuls/id/968814
Change Page: [ 1 ] [ 2 ] [ 3 ]
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
Today
|
New advisories:
|
6 |
|
New vulnerabilities:
|
23 |
|
Updated advisories:
|
66 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
6th Nov, 2009
|
New advisories:
|
17 |
|
New vulnerabilities:
|
65 |
|
Updated advisories:
|
21 |
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|
|
|
Send Feedback to Secunia
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|
|
|
|