Уязвимость повреждения памяти в Firefox и Thunderbird, позволяющая выполнять произвольный код
Описание
В Firefox версий 50.1 и Firefox ESR 45.6 были обнаружены ошибки (баги), связанные с безопасностью памяти. Некоторые из этих ошибок демонстрируют признаки повреждения памяти. Считается, что при определенных усилиях эти уязвимости способны быть использованы для выполнения произвольного кода.
Затронутые версии ПО
- Thunderbird версий ниже 45.7
- Firefox ESR версий ниже 45.7
- Firefox версий ниже 51
Тип уязвимости
- Повреждение памяти
- Выполнение произвольного кода
Ссылки
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue Tracking
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Third Party Advisory
- Third Party Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Issue Tracking
- Third Party Advisory
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Одно из
Одно из
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. ...
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
EPSS
9.8 Critical
CVSS3
7.5 High
CVSS2