Lucene search

K
freebsdFreeBSDB3FCB387-DE4B-11E2-B1C6-0025905A4771
HistoryJun 25, 2013 - 12:00 a.m.

mozilla -- multiple vulnerabilities

2013-06-2500:00:00
vuxml.freebsd.org
9

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.13 Low

EPSS

Percentile

95.5%

The Mozilla Project reports:

Miscellaneous memory safety hazards (rv:22.0 / rv:17.0.7)
Title: Memory corruption found using Address Sanitizer
Privileged content access and execution via XBL
Arbitrary code execution within Profiler
Execution of unmapped memory through onreadystatechange
Data in the body of XHR HEAD requests leads to CSRF attacks
SVG filters can lead to information disclosure
PreserveWrapper has inconsistent behavior
Sandbox restrictions not applied to nested frame elements
X-Frame-Options ignored when using server push with multi-part
responses
XrayWrappers can be bypassed to run user defined methods in a
privileged context
getUserMedia permission dialog incorrectly displays location
Homograph domain spoofing in .com, .net and .name
Inaccessible updater can lead to local privilege escalation

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

0.13 Low

EPSS

Percentile

95.5%