Уязвимость DoS атаки и выполнения произвольного кода в Mozilla Firefox, Thunderbird и SeaMonkey из-за повреждения памяти при использовании некорректных XSLT стилей
Описание
в Mozilla Firefox, Thunderbird и SeaMonkey обнаружена уязвимость, позволяющая злоумышленникам вызвать DoS атаку (повреждение памяти и аварийное завершение работы приложения) или, возможно, выполнить произвольный код. Это становится возможным при использовании некорректно сформированного XSLT стиля, встроенного в документ.
Затронутые версии ПО
- Mozilla Firefox версий до 3.6.26 и от 4.x до 9.0
- Thunderbird версий до 3.1.18 и от 5.0 до 9.0
- SeaMonkey версий до 2.7
Тип уязвимости
- Подмена данных
- Выполнение произвольного кода
- DoS атака
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Issue TrackingVendor Advisory
- Issue TrackingPatchVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before ...
Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.
EPSS
9.3 Critical
CVSS2