Описание
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
hardy | ignored | end of life |
lucid | released | 3.6.20+build1+nobinonly-0ubuntu0.10.04.1 |
maverick | released | 3.6.20+build1+nobinonly-0ubuntu0.10.10.1 |
natty | released | 6.0+build1+nobinonly-0ubuntu0.11.04.1 |
oneiric | not-affected | |
precise | not-affected | |
quantal | not-affected | |
upstream | released | 6.0 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | needs-triage | Ubuntu source uses 3.6.x |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | DNE | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | needs-triage | Ubuntu source uses 3.6.x |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | not-affected | |
maverick | not-affected | |
natty | not-affected | |
oneiric | not-affected | |
precise | DNE | |
quantal | DNE | |
upstream | not-affected |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
hardy | ignored | end of life |
lucid | released | 3.1.12+build1+nobinonly-0ubuntu0.10.04.1 |
maverick | released | 3.1.12+build1+nobinonly-0ubuntu0.10.10.1 |
natty | released | 3.1.12+build1+nobinonly-0ubuntu0.11.04.1 |
oneiric | not-affected | |
precise | not-affected | |
quantal | not-affected | |
upstream | released | 3.1.12, 6.0 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | released | 1.9.2.20+build1+nobinonly-0ubuntu0.10.04.1 |
maverick | released | 1.9.2.20+build1+nobinonly-0ubuntu0.10.10.1 |
natty | released | 1.9.2.27+build1+nobinonly-0ubuntu0.11.04.1 |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | released | 1.9.2.20 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | DNE | |
lucid | DNE | |
maverick | DNE | |
natty | ignored | end of life |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | needed |
Показывать по
EPSS
10 Critical
CVSS2
Связанные уязвимости
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox be ...
The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."
EPSS
10 Critical
CVSS2