LWN.net Logo

mozilla: multiple vulnerabilities

Package(s):mozilla CVE #(s):CVE-2010-1201 CVE-2010-0183 CVE-2008-5913
Created:June 24, 2010 Updated:January 21, 2011
Description:

From CVE-2010-1201: Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

From the Red Hat Bugzilla entry for CVE-2010-0183: Security researcher wushi of team509 reported that the frame construction process for certain types of menus could result in a menu containing a pointer to a previously freed menu item. During the cycle collection process this freed item could be accessed, resulting in the execution of a section of code potentially controlled by an attacker.

From the Red Hat Bugzilla entry for CVE-2008-5913: An unspecified function in the JavaScript implementation in Mozilla Firefox creates and exposes a "temporary footprint" when there is a current login to a web site, which makes it easier for remote attackers to trick a user into acting upon a spoofed pop-up message, aka an "in-session phishing attack."

Alerts:
MeeGo MeeGo-SA-10:39 2010-10-09
MeeGo MeeGo-SA-10:12 2010-08-03
CentOS CESA-2010:0500 2010-08-06
Ubuntu USN-930-5 2010-07-23
Ubuntu USN-930-4 2010-07-23
Fedora FEDORA-2010-11361 2010-07-23
Fedora FEDORA-2010-11361 2010-07-23
Mandriva MDVSA-2010:125 2010-06-24
Fedora FEDORA-2010-10361 2010-06-24
Fedora FEDORA-2010-10344 2010-06-24
Fedora FEDORA-2010-10361 2010-06-24
Fedora FEDORA-2010-10344 2010-06-24
Fedora FEDORA-2010-10363 2010-06-24
Fedora FEDORA-2010-10329 2010-06-24
SUSE SUSE-SA:2010:030 2010-07-09
openSUSE openSUSE-SU-2010:0358-2 2010-06-22
openSUSE openSUSE-SU-2010:0358-1 2010-07-07
Pardus 2010-89 2010-06-30
Ubuntu USN-930-2 2010-06-29
Ubuntu USN-930-1 2010-06-29
Fedora FEDORA-2010-10361 2010-06-24
Fedora FEDORA-2010-10344 2010-06-24
Fedora FEDORA-2010-10361 2010-06-24
Fedora FEDORA-2010-10344 2010-06-24
Fedora FEDORA-2010-10361 2010-06-24
Fedora FEDORA-2010-10344 2010-06-24
Ubuntu USN-943-1 2010-07-06
Debian DSA-2064-1 2010-06-27
Fedora FEDORA-2010-10361 2010-06-24
Ubuntu USN-930-3 2010-06-30
CentOS CESA-2010:0501 2010-06-24
Fedora FEDORA-2010-10361 2010-06-24
Fedora FEDORA-2010-10344 2010-06-24
Fedora FEDORA-2010-10344 2010-06-24

(Log in to post comments)

Copyright © 2012, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds