|
|
Log in / Subscribe / Register

mozilla: multiple vulnerabilities

Package(s):firefox, thunderbird, seamonkey, xulrunner CVE #(s):CVE-2011-1187 CVE-2011-2986 CVE-2012-0475
Created:April 27, 2012 Updated:July 23, 2012
Description: From the CVE entries:

Google Chrome before 10.0.648.127 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, related to an "error message leak." (CVE-2011-1187)

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. (CVE-2011-2986)

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields. (CVE-2012-0475)

Alerts:
openSUSE openSUSE-SU-2014:1100-1 Firefox 2014-09-09
Gentoo 201301-01 firefox 2013-01-07
Mageia MGASA-2012-0176 iceape 2012-07-21
Fedora FEDORA-2012-9079 thunderbird-lightning 2012-06-26
Fedora FEDORA-2012-9037 thunderbird-lightning 2012-06-26
Fedora FEDORA-2012-9079 thunderbird 2012-06-26
Fedora FEDORA-2012-9037 thunderbird 2012-06-26
Ubuntu USN-1430-3 thunderbird 2012-05-04
SUSE SUSE-SU-2012:0580-1 Mozilla Firefox 2012-05-02
SUSE SUSE-SU-2012:0688-1 MozillaFirefox 2012-06-02
Fedora FEDORA-2012-6610 perl-Gtk2-MozEmbed 2012-05-01
Fedora FEDORA-2012-6610 gnome-python2-extras 2012-05-01
Fedora FEDORA-2012-6610 xulrunner 2012-05-01
Fedora FEDORA-2012-6610 firefox 2012-05-01
Fedora FEDORA-2012-6738 thunderbird-lightning 2012-04-29
Fedora FEDORA-2012-6738 thunderbird 2012-04-29
Ubuntu USN-1430-2 ubufox 2012-04-27
Ubuntu USN-1430-1 firefox 2012-04-27
openSUSE openSUSE-SU-2012:0567-1 firefox, thunderbird, seamonkey, xulrunner 2012-04-27
Ubuntu USN-1430-4 apparmor 2012-06-12
Fedora FEDORA-2012-9001 thunderbird-lightning 2012-06-10
Fedora FEDORA-2012-9001 thunderbird 2012-06-10

to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds