Уязвимость use-after-free в функции nsNodeUtils::LastRelease компонента редактора в пользовательском интерфейсе редактирования таблиц в Mozilla Firefox, Firefox ESR, Thunderbird и SeaMonkey
Описание
Уязвимость типа use-after-free обнаружена в функции nsNodeUtils::LastRelease
в компоненте редактора, ответственном за редактирование таблиц в пользовательском интерфейсе. Эта уязвимость позволяет злоумышленникам выполнить произвольный код на удаленных системах путем некорректной работы сборщика мусора.
Затронутые версии ПО
- Mozilla Firefox версии до 26.0
- Mozilla Firefox ESR версии 24.x до 24.2
- Mozilla Thunderbird версии до 24.2
- Mozilla SeaMonkey версии до 2.23
Тип уязвимости
- Удалённое выполнение кода
Ссылки
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Mailing ListThird Party Advisory
- Third Party Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Third Party Advisory
- Third Party Advisory
- ExploitIssue TrackingVendor Advisory
Уязвимые конфигурации
Одно из
Одно из
Одно из
Одно из
Одно из
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2
Дефекты
Связанные уязвимости
Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
Use-after-free vulnerability in the nsNodeUtils::LastRelease function ...
Use-after-free vulnerability in the nsNodeUtils::LastRelease function in the table-editing user interface in the editor component in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code by triggering improper garbage collection.
EPSS
9.8 Critical
CVSS3
10 Critical
CVSS2