|
|
Log in / Subscribe / Register

mozilla: multiple vulnerabilities

Package(s):mozilla, firefox, thunderbird, seamonkey CVE #(s):CVE-2011-3658 CVE-2011-3660 CVE-2011-3661 CVE-2011-3663 CVE-2011-3665
Created:December 26, 2011 Updated:March 23, 2012
Description: From the Mandriva advisory:

The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAttrModified event handlers, which allows remote attackers to cause a denial of service (out-of-bounds memory access) or possibly have unspecified other impact via vectors involving removal of SVG elements (CVE-2011-3658).

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger a compartment mismatch associated with the nsDOMMessageEvent::GetData function, and unknown other vectors (CVE-2011-3660).

YARR, as used in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript (CVE-2011-3661).

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to capture keystrokes entered on a web page by using SVG animation accessKey events within that web page (CVE-2011-3663).

Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via an Ogg VIDEO element that is not properly handled after scaling (CVE-2011-3665).

Alerts:
openSUSE openSUSE-SU-2014:1100-1 Firefox 2014-09-09
Gentoo 201301-01 firefox 2013-01-07
openSUSE openSUSE-SU-2012:0567-1 firefox, thunderbird, seamonkey, xulrunner 2012-04-27
openSUSE openSUSE-SU-2012:0417-1 firefox, thunderbird 2012-03-27
Ubuntu USN-1401-2 thunderbird 2012-03-23
Ubuntu USN-1401-1 xulrunner-1.9.2 2012-03-19
Mandriva MDVSA-2012:031 firefox 2012-03-17
openSUSE openSUSE-SU-2012:0039-2 MozillaFirefox 2012-02-09
Ubuntu USN-1343-1 thunderbird 2012-01-24
Ubuntu USN-1306-2 firefox 2012-01-06
Ubuntu USN-1306-1 firefox 2012-01-06
openSUSE openSUSE-SU-2012:0007-1 seamonkey 2012-01-05
Mandriva MDVSA-2011:192 mozilla 2011-12-23

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds