Описание
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
lucid | ignored | end of life |
precise | released | 27.0+build1-0ubuntu0.12.04.1 |
quantal | released | 27.0+build1-0ubuntu0.12.10.1 |
saucy | released | 27.0+build1-0ubuntu0.13.10.1 |
upstream | released | 27.0 |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | released | 1:24.4.0+build1-0ubuntu1 |
lucid | ignored | end of life |
precise | released | 1:24.3.0+build2-0ubuntu0.12.04.1 |
quantal | released | 1:24.3.0+build2-0ubuntu0.12.10.1 |
saucy | released | 1:24.3.0+build2-0ubuntu0.13.10.1 |
upstream | released | 24.3.0 |
Показывать по
9.3 Critical
CVSS2
8.8 High
CVSS3
Связанные уязвимости
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x befor ...
RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.
Уязвимость пакета программ Mozilla SeaMonkey, позволяющая злоумышленнику выполнить произвольный код или выполнить отказ в обслуживании
9.3 Critical
CVSS2
8.8 High
CVSS3