Executive Summary
| Summary | |
|---|---|
| Title | New icedove packages fix several vulnerabilities |
| Informations | |||
|---|---|---|---|
| Name | DSA-1830 | First vendor Publication | 2009-07-12 |
| Vendor | Debian | Last vendor Modification | 2009-07-12 |
| Severity (Vendor) | N/A | Revision | 1 |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Several remote vulnerabilities have been discovered in the Icedove mail client, an unbranded version of the Thunderbird mail client. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-0040 The execution of arbitrary code might be possible via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables. (MFSA 2009-10) CVE-2009-0352 It is possible to execute arbitrary code via vectors related to the layout engine. (MFSA 2009-01) CVE-2009-0353 It is possible to execute arbitrary code via vectors related to the JavaScript engine. (MFSA 2009-01) CVE-2009-0652 Bjoern Hoehrmann and Moxie Marlinspike discovered a possible spoofing attack via Unicode box drawing characters in internationalized domain names. (MFSA 2009-15) CVE-2009-0771 Memory corruption and assertion failures have been discovered in the layout engine, leading to the possible execution of arbitrary code. (MFSA 2009-07) CVE-2009-0772 The layout engine allows the execution of arbitrary code ia vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection. (MFSA 2009-07) CVE-2009-0773 The JavaScript engine is prone to the execution of arbitrary code via several vectors. (MFSA 2009-07) CVE-2009-0774 The layout engine allows the execution of arbitrary code via vectors related to gczeal. (MFSA 2009-07) CVE-2009-0776 Georgi Guninski discovered that it is possible to obtain xml data via an issue related to the nsIRDFService. (MFSA 2009-09) CVE-2009-1302 The browser engine is prone to a possible memory corruption via several vectors. (MFSA 2009-14) CVE-2009-1303 The browser engine is prone to a possible memory corruption via the nsSVGElement::BindToTree function. (MFSA 2009-14) CVE-2009-1307 Gregory Fleischer discovered that it is possible to bypass the Same Origin Policy when opening a Flash file via the view-source: scheme. (MFSA 2009-17) CVE-2009-1832 The possible arbitrary execution of code was discovered via vectors involving "double frame construction." (MFSA 2009-24) CVE-2009-1392 Several issues were discovered in the browser engine as used by icedove, which could lead to the possible execution of arbitrary code. (MFSA 2009-24) CVE-2009-1836 Shuo Chen, Ziqing Mao, Yi-Min Wang and Ming Zhang reported a potential man-in-the-middle attack, when using a proxy due to insufficient checks on a certain proxy response. (MFSA 2009-27) CVE-2009-1838 moz_bug_r_a4 discovered that it is possible to execute arbitrary JavaScript with chrome privileges due to an error in the garbage-collection implementation. (MFSA 2009-29) CVE-2009-1841 moz_bug_r_a4 reported that it is possible for scripts from page content to run with elevated privileges and thus potentially executing arbitrary code with the object's chrome privileges. (MFSA 2009-32) No CVE id yet Bernd Jendrissek discovered a potentially exploitable crash when viewing a multipart/alternative mail message with a text/enhanced part. (MFSA 2009-33) For the stable distribution (lenny), these problems have been fixed in version 2.0.0.22-0lenny1. As indicated in the Etch release notes, security support for the Mozilla products in the oldstable distribution needed to be stopped before the end of the regular Etch security maintenance life cycle. You are strongly encouraged to upgrade to stable or switch to a still supported mail client. For the testing (squeeze) distribution these problems will be fixed soon. For the unstable distribution (sid), these problems have been fixed in version 2.0.0.22-1. We recommend that you upgrade your icedove packages. |
Original Source
| Url : http://www.debian.org/security/2009/dsa-1830 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-399 | Resource Management Errors |
| CWE-94 | Failure to Control Generation of Code ('Code Injection') |
| CWE-287 | Improper Authentication |
| CWE-200 | Information Exposure |
| CWE-20 | Improper Input Validation |
| CWE-16 | Configuration |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:6458 | |||
| Oval ID: | oval:org.mitre.oval:def:6458 | ||
| Title: | Libpng Library Uninitialized Pointer Arrays Memory Corruption Vulnerability | ||
| Description: | The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0040 |
Version: | 1 |
| Platform(s): | VMWare ESX Server 3 VMWare ESX Server 3.5 |
Product(s): | |
| Definition Synopsis: | |||
| Definition Id: oval:org.mitre.oval:def:10316 | |||
| Oval ID: | oval:org.mitre.oval:def:10316 | ||
| Title: | The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables. | ||
| Description: | The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file that triggers a free of an uninitialized pointer in (1) the png_read_png function, (2) pCAL chunk handling, or (3) setup of 16-bit gamma tables. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0040 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:11396 | |||
| Oval ID: | oval:org.mitre.oval:def:11396 | ||
| Title: | The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected. | ||
| Description: | The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0652 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6755 | |||
| Oval ID: | oval:org.mitre.oval:def:6755 | ||
| Title: | Mozilla Firefox, Thunderbird and Seamonkey memory corruption Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0771 |
Version: | 5 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6196 | |||
| Oval ID: | oval:org.mitre.oval:def:6196 | ||
| Title: | Mozilla Firefox memory corruption Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0771 |
Version: | 4 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6163 | |||
| Oval ID: | oval:org.mitre.oval:def:6163 | ||
| Title: | Mozilla Thunderbird memory corruption Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0771 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5250 | |||
| Oval ID: | oval:org.mitre.oval:def:5250 | ||
| Title: | Mozilla Seamonkey memory corruption Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0771 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:11314 | |||
| Oval ID: | oval:org.mitre.oval:def:11314 | ||
| Title: | The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures. | ||
| Description: | The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and assertion failures. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0771 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9609 | |||
| Oval ID: | oval:org.mitre.oval:def:9609 | ||
| Title: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption. | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0772 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6811 | |||
| Oval ID: | oval:org.mitre.oval:def:6811 | ||
| Title: | Mozilla Firefox, Thunderbird and Seamonkey Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0772 |
Version: | 5 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6097 | |||
| Oval ID: | oval:org.mitre.oval:def:6097 | ||
| Title: | Mozilla Firefox Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0772 |
Version: | 4 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5945 | |||
| Oval ID: | oval:org.mitre.oval:def:5945 | ||
| Title: | Mozilla Seamonkey Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0772 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5703 | |||
| Oval ID: | oval:org.mitre.oval:def:5703 | ||
| Title: | Mozilla Thunderbird Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to nsCSSStyleSheet::GetOwnerNode, events, and garbage collection, which triggers memory corruption. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0772 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6708 | |||
| Oval ID: | oval:org.mitre.oval:def:6708 | ||
| Title: | Mozilla Firefox, Thunderbird and Seamonkey Denial of Service and arbitrary code execution Vulnerabilities | ||
| Description: | The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0773 |
Version: | 5 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6141 | |||
| Oval ID: | oval:org.mitre.oval:def:6141 | ||
| Title: | Mozilla Firefox Denial of Service and arbitrary code execution Vulnerabilities | ||
| Description: | The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0773 |
Version: | 4 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5980 | |||
| Oval ID: | oval:org.mitre.oval:def:5980 | ||
| Title: | Mozilla Thunderbird Denial of Service and arbitrary code execution Vulnerabilities | ||
| Description: | The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0773 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5856 | |||
| Oval ID: | oval:org.mitre.oval:def:5856 | ||
| Title: | Mozilla Seamonkey Denial of Service and arbitrary code execution Vulnerabilities | ||
| Description: | The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0773 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:10491 | |||
| Oval ID: | oval:org.mitre.oval:def:10491 | ||
| Title: | The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang. | ||
| Description: | The JavaScript engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) a splice of an array that contains "some non-set elements," which causes jsarray.cpp to pass an incorrect argument to the ResizeSlots function, which triggers memory corruption; (2) vectors related to js_DecompileValueGenerator, jsopcode.cpp, __defineSetter__, and watch, which triggers an assertion failure or a segmentation fault; and (3) vectors related to gczeal, __defineSetter__, and watch, which triggers a hang. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0773 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6945 | |||
| Oval ID: | oval:org.mitre.oval:def:6945 | ||
| Title: | Mozilla Firefox, Thunderbird and Seamonkey gczeal (vector) Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0774 |
Version: | 5 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6121 | |||
| Oval ID: | oval:org.mitre.oval:def:6121 | ||
| Title: | Mozilla Thunderbird gczeal (vector) Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0774 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6057 | |||
| Oval ID: | oval:org.mitre.oval:def:6057 | ||
| Title: | Mozilla Seamonkey gczeal (vector) Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0774 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5947 | |||
| Oval ID: | oval:org.mitre.oval:def:5947 | ||
| Title: | Mozilla Firefox gczeal (vector) Denial of Service Vulnerability | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0774 |
Version: | 4 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:11138 | |||
| Oval ID: | oval:org.mitre.oval:def:11138 | ||
| Title: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773. | ||
| Description: | The layout engine in Mozilla Firefox 2 and 3 before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to gczeal, a different vulnerability than CVE-2009-0773. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0774 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9241 | |||
| Oval ID: | oval:org.mitre.oval:def:9241 | ||
| Title: | nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect. | ||
| Description: | nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-0776 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:7390 | |||
| Oval ID: | oval:org.mitre.oval:def:7390 | ||
| Title: | Mozilla Firefox, Thunderbird and Seamonkey security bypass Vulnerability | ||
| Description: | nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0776 |
Version: | 5 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6191 | |||
| Oval ID: | oval:org.mitre.oval:def:6191 | ||
| Title: | Mozilla Thunderbird security bypass Vulnerability | ||
| Description: | nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0776 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6017 | |||
| Oval ID: | oval:org.mitre.oval:def:6017 | ||
| Title: | Mozilla Seamonkey security bypass Vulnerability | ||
| Description: | nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0776 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5956 | |||
| Oval ID: | oval:org.mitre.oval:def:5956 | ||
| Title: | Mozilla Firefox security bypass Vulnerability | ||
| Description: | nsIRDFService in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey before 1.1.15 allows remote attackers to bypass the same-origin policy and read XML data from another domain via a cross-domain redirect. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-0776 |
Version: | 4 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:7030 | |||
| Oval ID: | oval:org.mitre.oval:def:7030 | ||
| Title: | Mozilla Thunderbird, Seamonkey and Firefox Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1302 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird Mozilla Seamonkey Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6170 | |||
| Oval ID: | oval:org.mitre.oval:def:6170 | ||
| Title: | Mozilla Thunderbird Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1302 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6070 | |||
| Oval ID: | oval:org.mitre.oval:def:6070 | ||
| Title: | Mozilla Seamonkey Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1302 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5527 | |||
| Oval ID: | oval:org.mitre.oval:def:5527 | ||
| Title: | Mozilla Firefox Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1302 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:10106 | |||
| Oval ID: | oval:org.mitre.oval:def:10106 | ||
| Title: | The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors. | ||
| Description: | The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to (1) nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3) nsComputedDOMStyle::GetWidth, (4) the xslt_attributeset_ImportSameName.html test case for the XSLT stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener, (6) IsBindingAncestor, (7) PL_DHashTableOperate and nsEditor::EndUpdateViewBatch, and (8) gfxSkipCharsIterator::SetOffsets, and other vectors. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1302 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9455 | |||
| Oval ID: | oval:org.mitre.oval:def:9455 | ||
| Title: | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. | ||
| Description: | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1303 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6646 | |||
| Oval ID: | oval:org.mitre.oval:def:6646 | ||
| Title: | Mozilla Thunderbird, Firefox and Seamonkey Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1303 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox Mozilla Thunderbird Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6151 | |||
| Oval ID: | oval:org.mitre.oval:def:6151 | ||
| Title: | Mozilla Thunderbird Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1303 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5992 | |||
| Oval ID: | oval:org.mitre.oval:def:5992 | ||
| Title: | Mozilla Firefox Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1303 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5810 | |||
| Oval ID: | oval:org.mitre.oval:def:5810 | ||
| Title: | Mozilla Seamonkey Denial of Service Vulnerability | ||
| Description: | The browser engine in Mozilla Firefox before 3.0.9, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers to cause a denial of service (application crash) and possibly trigger memory corruption via vectors related to nsSVGElement::BindToTree. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1303 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:7008 | |||
| Oval ID: | oval:org.mitre.oval:def:7008 | ||
| Title: | Mozilla Thunderbird, Firefox and Seamonkey arbitrary code execution Vulnerability | ||
| Description: | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1307 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird Mozilla Seamonkey Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6266 | |||
| Oval ID: | oval:org.mitre.oval:def:6266 | ||
| Title: | Mozilla Thunderbird arbitrary code execution Vulnerability | ||
| Description: | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1307 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Thunderbird |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:6154 | |||
| Oval ID: | oval:org.mitre.oval:def:6154 | ||
| Title: | Mozilla Firefox arbitrary code execution Vulnerability | ||
| Description: | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1307 |
Version: | 3 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Firefox |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:5933 | |||
| Oval ID: | oval:org.mitre.oval:def:5933 | ||
| Title: | Mozilla Seamonkey arbitrary code execution Vulnerability | ||
| Description: | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2009-1307 |
Version: | 1 |
| Platform(s): | Microsoft Windows XP Microsoft Windows Server 2003 Microsoft Windows Vista |
Product(s): | Mozilla Seamonkey |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:10972 | |||
| Oval ID: | oval:org.mitre.oval:def:10972 | ||
| Title: | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. | ||
| Description: | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1307 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9501 | |||
| Oval ID: | oval:org.mitre.oval:def:9501 | ||
| Title: | The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors. | ||
| Description: | The browser engine in Mozilla Firefox 3 before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsEventStateManager::GetContentState and nsNativeTheme::CheckBooleanAttr; (2) UnhookTextRunFromFrames and ClearAllTextRunReferences; (3) nsTextFrame::ClearTextRun; (4) IsPercentageAware; (5) PL_DHashTableFinish; (6) nsListBoxBodyFrame::GetNextItemBox; (7) AtomTableClearEntry, related to the atom table, DOM mutation events, and Unicode surrogates; (8) nsHTMLEditor::HideResizers; and (9) nsWindow::SetCursor, related to changing the cursor; and other vectors. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1392 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:10237 | |||
| Oval ID: | oval:org.mitre.oval:def:10237 | ||
| Title: | Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction." | ||
| Description: | Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors involving "double frame construction." | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1832 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:11764 | |||
| Oval ID: | oval:org.mitre.oval:def:11764 | ||
| Title: | Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack. | ||
| Description: | Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 use the HTTP Host header to determine the context of a document provided in a non-200 CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1836 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:11080 | |||
| Oval ID: | oval:org.mitre.oval:def:11080 | ||
| Title: | The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler. | ||
| Description: | The garbage-collection implementation in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 sets an element's owner document to null in unspecified circumstances, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted event handler, related to an incorrect context for this event handler. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1838 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9815 | |||
| Oval ID: | oval:org.mitre.oval:def:9815 | ||
| Title: | js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter. | ||
| Description: | js/src/xpconnect/src/xpcwrappedjsclass.cpp in Mozilla Firefox before 3.0.11, Thunderbird before 2.0.0.22, and SeaMonkey before 1.1.17 allows remote attackers to execute arbitrary web script with the privileges of a chrome object, as demonstrated by the browser sidebar and the FeedWriter. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-1841 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
| Definition Id: oval:org.mitre.oval:def:9994 | |||
| Oval ID: | oval:org.mitre.oval:def:9994 | ||
| Title: | Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type. | ||
| Description: | Mozilla Thunderbird before 2.0.0.22 and SeaMonkey before 1.1.17 allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a multipart/alternative e-mail message containing a text/enhanced part that triggers access to an incorrect object type. | ||
| Family: | unix | Class: | vulnerability |
| Reference(s): | CVE-2009-2210 |
Version: | 5 |
| Platform(s): | Red Hat Enterprise Linux 3 CentOS Linux 3 Red Hat Enterprise Linux 4 CentOS Linux 4 Oracle Linux 4 Red Hat Enterprise Linux 5 CentOS Linux 5 Oracle Linux 5 |
Product(s): | |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 55532 | Mozilla Multiple Products Crafted multipart/alternative E-mail Message Remote... |
| 55160 | Mozilla Multiple Products Proxy Server CONNECT Response Manipulation SSL MiTM... |
| 55159 | Mozilla Multiple Products xpcwrappedjsclass.cpp JavaScript Chrome Privilege E... |
| 55157 | Mozilla Multiple Products Garbage-collection Implementation Crafted Event Han... |
| 55148 | Mozilla Multiple Products Double Frame Construction Memory Corruption |
| 55147 | Mozilla Multiple Products Browser Engine Multiple Unspecified Memory Corruption |
| 55146 | Mozilla Multiple Products Browser Engine xulrunner nsWindow::SetCursor Functi... |
| 55145 | Mozilla Multiple Products Browser Engine nsHTMLEditor::HideResizers contentEd... |
| 55144 | Mozilla Multiple Products Browser Engine AtomTableClearEntry Multiple Method ... |
| 55143 | Mozilla Multiple Products Browser Engine nsListBoxBodyFrame::GetNextItemBox x... |
| 55142 | Mozilla Multiple Products Browser Engine PL_DHashTableFinish style Tag Handli... |
| 55141 | Mozilla Multiple Products Browser Engine IsPercentageAware Function Memory Co... |
| 55140 | Mozilla Multiple Products Browser Engine nsTextFrame::ClearTextRun Accessibil... |
| 55139 | Mozilla Multiple Products Browser Engine UnhookTextRunFromFrames / ClearAllTe... |
| 55138 | Mozilla Multiple Products Browser Engine nsEventStateManager::GetContentState... |
| 53972 | Mozilla Multiple Products nsAsyncInstantiateEvent::Run() Frame Handling Memor... |
| 53971 | Mozilla Multiple Products nsSVGElement::BindToTree svg Handling Memory Corrup... |
| 53966 | Mozilla Multiple Products gfxSkipCharsIterator::SetOffsets Memory Corruption |
| 53965 | Mozilla Multiple Products nsStyleContext::Destroy() DOMAttrModified Window Ha... |
| 53964 | Mozilla Multiple Products PL_DHashTableOperate / nsEditor::EndUpdateViewBatch... |
| 53963 | Mozilla Multiple Products XSLT Stylesheet Compiling Memory Corruption |
| 53962 | Mozilla Multiple Products nsComputedDOMStyle::GetWidth Memory Corruption |
| 53961 | Mozilla Multiple Products nsXULDocument::SynchronizeBroadcastListener Memory ... |
| 53960 | Mozilla Multiple Products IsBindingAncestor Frame Handling Memory Corruption |
| 53958 | Mozilla Multiple Products view-source: Scheme Adobe Flash Same-origin Policy ... |
| 53317 | libpng 16-bit Gamma Table Handling Uninitialised Pointer Free Arbitrary Code ... |
| 53316 | libpng pCAL Chunk Handling Uninitialised Pointer Free Arbitrary Code Execution |
| 53315 | libpng png_read_png Function Uninitialised Pointer Free Arbitrary Code Execution |
| 52659 | Mozilla Firefox IDN Homoglyph Character Literal Rendering URI Spoofing Weakness |
| 52451 | Mozilla Multiple Products nsIRDFService Cross-domain Redirect Same-origin Pol... |
| 52449 | Mozilla Multiple Products JavaScript Engine Multiple Vector Unspecified DoS |
| 52448 | Mozilla Multiple Products JavaScript Engine jsopcode.cpp Multiple Vector Arbi... |
| 52447 | Mozilla Multiple Products JavaScript Engine jsarray.cpp ResizeSlots Function ... |
| 52446 | Mozilla Multiple Products Layout Engine gczeal Unspecified Code Execution |
| 52445 | Mozilla Multiple Products Layout Engine nsCSSStyleSheet::GetOwnerNode Functio... |
| 52444 | Mozilla Multiple Products Layout Engine Multiple Unspecified Memory Corruptions |
| 51940 | Mozilla Multiple Products Layout Engine nsStyleContext::Destroy Multiple Meth... |
| 51939 | Mozilla Multiple Products Layout Engine nsOverflowContinuationTracker::Insert... |
| 51938 | Mozilla Multiple Products Layout Engine nsContainerFrame::ReflowOverflowConta... |
| 51937 | Mozilla Multiple Products Layout Engine nsViewManager::Composite() Layout Obj... |
| 51936 | Mozilla Multiple Products Layout Engine nsTransactionItem.cpp PlaceholderTxn:... |
| 51935 | Mozilla Multiple Products Layout Engine nsAttributeTextNode GetStrokeDash* Me... |
| 51934 | Mozilla Multiple Products Layout Engine nsStyleContext::Release Memory Corrup... |
| 51933 | Mozilla Multiple Products Layout Engine nsContainerFrame.cpp Frame Tree Handl... |
| 51932 | Mozilla Multiple Products Layout Engine nsContentUtils::ComparePosition Memor... |
| 51931 | Mozilla Multiple Products Layout Engine File Open Dialog input type Manipulat... |
| 51929 | Mozilla Multiple Products JavaScript Engine Unspecified Memory Corruption |

DSA-1830
(Critical)
(High)
(Medium)






