Уязвимость DoS атаки и возможная компрометация памяти в Mozilla Firefox, Thunderbird и SeaMonkey
Описание
В браузерах Mozilla Firefox версий до 2.0.0.12, Thunderbird версий до 2.0.0.12, и SeaMonkey версий до 1.1.8 существует уязвимость, которая позволяет злоумышленникам осуществить DoS атаку и возможно повреждение памяти через методы, такие как nsTableFrame::GetFrameAtOrBefore, nsAccessibilityService::GetAccessible, nsBindingManager::GetNestedInsertionPoint, nsXBLPrototypeBinding::AttributeChanged, nsColumnSetFrame::GetContentInsertionFrame, nsLineLayout::TrimTrailingWhiteSpaceIn и другие.
Затронутые версии ПО
- Mozilla Firefox до версии 2.0.0.12
- Thunderbird до версии 2.0.0.12
- SeaMonkey до версии 1.1.8
Тип уязвимости
- DoS атака
- Возможная компрометация памяти
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedInsertionPoint, (4) nsXBLPrototypeBinding::AttributeChanged, (5) nsColumnSetFrame::GetContentInsertionFrame, and (6) nsLineLayout::TrimTrailingWhiteSpaceIn methods, and other vectors.
The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedInsertionPoint, (4) nsXBLPrototypeBinding::AttributeChanged, (5) nsColumnSetFrame::GetContentInsertionFrame, and (6) nsLineLayout::TrimTrailingWhiteSpaceIn methods, and other vectors.
The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird bef ...
The browser engine in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to the (1) nsTableFrame::GetFrameAtOrBefore, (2) nsAccessibilityService::GetAccessible, (3) nsBindingManager::GetNestedInsertionPoint, (4) nsXBLPrototypeBinding::AttributeChanged, (5) nsColumnSetFrame::GetContentInsertionFrame, and (6) nsLineLayout::TrimTrailingWhiteSpaceIn methods, and other vectors.
ELSA-2008-0103: Critical: firefox security update (CRITICAL)
EPSS
9.3 Critical
CVSS2