Уязвимость use-after-free в реализации функции mozVibrate в библиотеке Vibrate в Mozilla Firefox, Thunderbird и SeaMonkey, позволяющая удалённо выполнять произвольный код
Описание
Уязвимость использования после высвобождения (use-after-free) обнаружена в реализации функции mozVibrate в библиотеке Vibrate в Mozilla Firefox, Thunderbird и SeaMonkey. Эта уязвимость позволяет удалённым злоумышленникам выполнять произвольный код, используя векторы, связанные с указателем domDoc.
Затронутые версии ПО
- Mozilla Firefox версии до 18.0
- Mozilla Firefox ESR версии 17.x до 17.0.2
- Mozilla Thunderbird версии до 17.0.2
- Mozilla Thunderbird ESR версии 17.x до 17.0.2
- SeaMonkey версии до 2.15
Тип уязвимости
Удалённое выполнение кода
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitIssue TrackingPatchVendor Advisory
- Third Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- ExploitIssue TrackingPatchVendor Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
EPSS
9.3 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in the mozVibrate implementation in the Vibrate library in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors related to the domDoc pointer.
Use-after-free vulnerability in the mozVibrate implementation in the Vibrate library in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors related to the domDoc pointer.
Use-after-free vulnerability in the mozVibrate implementation in the V ...
Use-after-free vulnerability in the mozVibrate implementation in the Vibrate library in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 17.x before 17.0.2, and SeaMonkey before 2.15 allows remote attackers to execute arbitrary code via vectors related to the domDoc pointer.
EPSS
9.3 Critical
CVSS2