Lucene search

K
nessusTenable6307.PRM
HistoryFeb 07, 2012 - 12:00 a.m.

Mozilla Firefox 3.6.x < 3.6.26 Multiple Vulnerabilities

2012-02-0700:00:00
Tenable
www.tenable.com
12

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.898

Percentile

98.8%

The remote host has a web browser installed that is vulnerable to multiple attack vectors.

Versions of Firefox 3.6.x earlier than 3.6.26 are potentially affected by the following security issues :

  • A use-after-free error exists related to removed nsDOMAttribute child nodes. (CVE-2011-3659)
  • The IPv6 literal syntax in web addresses is not being properly enforced. (CVE-2011-3670)
  • Various memory safety issues exist. (CVE-2012-0442)
  • Memory corruption errors exist related to the decoding of Ogg Vorbis files and processing of malformed XSLT stylesheets. (CVE-2012-0444, CVE-2012-0449)
Binary data 6307.prm

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS

0.898

Percentile

98.8%