mozilla: multiple vulnerabilities
Package(s): | mozilla | CVE #(s): | CVE-2005-4134 CVE-2006-0292 CVE-2006-0296 | ||||||||||||||||||||||||||||||||||||
Created: | February 2, 2006 | Updated: | May 4, 2006 | ||||||||||||||||||||||||||||||||||||
Description: | Mozilla has three new vulnerabilities.
The Javascript interpreter has a problem with
dereferencing objects. A user can visit a specially crafted web page
which can crash the browser or cause it to execute arbitrary code. The XULDocument.persist() function has a bug that can be triggered by viewing specially crafted web sites, RDF data can be injected into the localstore.rdf file, allowing arbitrary javascript code to be executed. The Mozilla history saving mechanism is vulnerable to a denial of service attack, visiting sites with extra-long titles can cause a crash or very slow startup the next time the browser is run. | ||||||||||||||||||||||||||||||||||||||
Alerts: |
|