Уязвимость use-after-free в Mozilla Firefox, Thunderbird и SeaMonkey, позволяющая удаленно выполнять произвольный код через некорректные уведомления AttributeChildRemoved
Описание
Уязвимость типа use-after-free обнаружена в приложениях Mozilla Firefox, Thunderbird и SeaMonkey. Эта уязвимость может позволить удалённым злоумышленникам выполнить произвольный код. Проблема связана с некорректными уведомлениями AttributeChildRemoved
, которые затрагивают доступ к удалённым дочерним узлам nsDOMAttribute
.
Затронутые версии ПО
- Mozilla Firefox версии до 3.6.26 и версии 4.x до 9.0
- Thunderbird версии до 3.1.18 и версии 5.0 до 9.0
- SeaMonkey версии до 2.7
Тип уязвимости
Удалённое выполнение кода
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- ExploitIssue TrackingPatchVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- ExploitIssue TrackingPatchVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x ...
Use-after-free vulnerability in Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 might allow remote attackers to execute arbitrary code via vectors related to incorrect AttributeChildRemoved notifications that affect access to removed nsDOMAttribute child nodes.
EPSS
9.3 Critical
CVSS2