Уязвимость удалённого выполнения произвольного кода в методе crypto.generateCRMFRequest в Mozilla Firefox, Thunderbird, Mozilla Suite и SeaMonkey
Описание
Неуточнённая уязвимость в Mozilla Firefox и Thunderbird версий 1.x до версии 1.5.0.2 и 1.0.x до версии 1.0.8, в Mozilla Suite до версии 1.7.13 и SeaMonkey до версии 1.0.1 позволяет злоумышленникам выполнять произвольный код удалённо. Это связано с методами, относящимися к crypto.generateCRMFRequest.
Затронутые версии ПО
- Mozilla Firefox версии 1.x до 1.5.0.2
- Mozilla Firefox версии 1.0.x до 1.0.8
- Thunderbird версии 1.x до 1.5.0.2
- Thunderbird версии 1.0.x до 1.0.8
- Mozilla Suite до версии 1.7.13
- SeaMonkey до версии 1.0.1
Тип уязвимости
Удалённое выполнение кода
Ссылки
- Broken Link
- Broken Link
- Broken Link
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x befor ...
Unspecified vulnerability in Mozilla Firefox and Thunderbird 1.x before 1.5.0.2 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0.1 allows remote attackers to execute arbitrary code via unknown vectors related to the crypto.generateCRMFRequest method.
EPSS
9.3 Critical
CVSS2