Уязвимость use-after-free в функции PresShell::DispatchSynthMouseMove в Mozilla Firefox, Thunderbird и SeaMonkey
Описание
Уязвимость use-after-free в функции PresShell::DispatchSynthMouseMove
позволяет злоумышленникам выполнять произвольный код или вызывать DoS атаки через повреждение памяти в куче. Уязвимость связана с функцией RestyleManager::GetHoverGeneration
и может быть активирована с помощью векторов, включающих синтетическое движение мыши.
Затронутые версии ПО
- Mozilla Firefox до версии 26.0
- Firefox ESR версия 24.x до версии 24.2
- Thunderbird до версии 24.2
- SeaMonkey до версии 2.23
Тип уязвимости
- Удалённое выполнение кода
- DoS атака (повреждение памяти в куче)
Дополнительные сведения
- CWE-416: Use After Free
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
Одно из
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove ...
Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related to the RestyleManager::GetHoverGeneration function.
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2