Multiple vulnerabilities have been reported in Mozilla Firefox, which can be exploited by malicious people to gain knowledge of certain information, conduct cross-site scripting attacks, and potentially compromise a user's system.
2) An error when reducing the CPU's floating point precision, which may happen on Windows when loading a plugin creating a Direct3D device, may cause the "js_dtoa()" function to not exit and instead cause a memory corruption.
3) A boundary error when setting the cursor to a Windows bitmap using the CSS cursor property can be exploited to cause a heap-based buffer overflow.
5) An error in LiveConnect causes an already freed object to be used and may potentially allow execution of arbitrary code.
7) An error within the handling of SVG comment objects can be exploited to cause a memory corruption and allows execution of arbitrary code by appending an SVG comment object from one document into another type of document (e.g. HTML).
8) The "Feed Preview" feature of Firefox 2.0 may leak feed-browsing habits to websites when retrieving the icons of installed web-based feed viewers.
9) A Function prototype regression in Firefox 2.0 can be exploited to execute arbitrary HTML and script code in a user's browser session.
Solution: Update to version 184.108.40.206 or 220.127.116.11.
Provided and/or discovered by: The vendor credits the following:
1) Andrew Miller, David Baron, moz_bug_r_a4, Georgi Guninski, Jesse Ruderman, Olli Pettay, Igor Bukanov, and Vladimir Vukicevic.
2) Keith Victor
3) Frederik Reiss
5) Steven Michaud
7) An anonymous person via ZDI.
8) Jared Breland
Do you have additional information related to this advisory?
Please provide information about patches, mitigating factors, new versions, exploits, faulty patches, links, and other relevant data by posting comments to this Advisory. You can also send this
information to email@example.com
Subject: Mozilla Firefox Multiple Vulnerabilities
No posts yet
You must be logged in to post a comment.
Secunia Customer Login
Not a customer already?
Learn more about how our market leading Vulnerability Management solutions can help you manage risk and ensure compliance.