Firefox & Thunderbird propusti / ažuriranje

Firefox & Thunderbird propusti / ažuriranje

offline
  • dr_Bora  Male
  • Anti Malware Fighter
    Rank 2
  • Pridružio: 24 Jul 2007
  • Poruke: 12280
  • Gde živiš: Höganäs, SE

CVE-2011-3658

The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements.


CVE-2011-3660

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors.


CVE-2011-3661

YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.


CVE-2011-3663

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page by using SVG animation accessKey events within that web page.


CVE-2011-3664

Mozilla Firefox before 9.0, Thunderbird before 9.0, and SeaMonkey before 2.6 on Mac OS X do not properly handle certain DOM frame deletions by plugins, which allows remote attackers to cause a denial of service (incorrect pointer dereference and application crash) or possibly have unspecified other impact via a crafted web site.


CVE-2011-3665

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an Ogg VIDEO element that is not properly handled after scaling.


CVE-2011-3666

Mozilla Firefox before 3.6.25 and Thunderbird before 3.1.17 on Mac OS X do not consider .jar files to be executable files, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted file. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-2372 on Mac OS X.


Source: National Vulnerability Database



Propusti su ispravljeni u najnovijim verzijama programa.

[Link mogu videti samo ulogovani korisnici]

[Link mogu videti samo ulogovani korisnici]



Registruj se da bi učestvovao u diskusiji. Registrovanim korisnicima se NE prikazuju reklame unutar poruka.
Ko je trenutno na forumu
 

Ukupno su 2329 korisnika na forumu :: 89 registrovanih, 6 sakrivenih i 2234 gosta   ::   [ Administrator ] [ Supermoderator ] [ Moderator ] :: Detaljnije

Najviše korisnika na forumu ikad bilo je 13297 - dana 20 Jan 2026 17:42

Korisnici koji su trenutno na forumu:
Korisnici trenutno na forumu: 357magnum, 6.5lapua, Ailton, Arsenije, Avladi, banebeograd, Bojke549, boro975, BORUTUS, Brankojle, Bubimir, C-Gun, CikaKURE, darkojbn, Dimitrije Paunovic, djboj, DonRumataEstorski, drale12, DzigiNS, dzoni19, Ezbuck, feanor, FOX, Gonga, Igor Antonic, Insan, jalos, Jester, Jovan1997, Kajzer Soze, keyz, kibihrchak, KizJ, Knovakov, Kozi-RS, Kredit, Kruger, Kubovac, kybonacci, Leonov, LostInSpaceandTime, Lucije Kvint, medaTT, mercedesamg, Mihajlo, MikeHammer, miki kv, milanstankovic087, milenko crazy north, milospobedic, Miloš.90, milutin134, mitja2512, Naj-Turs, nebkv, orfanel, Oscar, pceklic, pera bager, Petarvu, Pilence, RajkoB, Ripanjac, SamostalniReferent, Seeker, Semberija, shota91, sistem22, skvara, Srna, Steeeefan, Stod, SympathyForTheDevil, TheDictator, tm, TRAVUNIJA, Uros Cuore Sportivo, uruk, vathra, Velizar Laro, vladaa012, Volkhov-M, Wepp, wizzardone, wolf1, yrraf, Zastava, zeo, 2001