Beschreibung
Multiple serious vulnerabilities were found in Mozilla Firefox and Mozilla Firefox ESR. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause denial of service, bypass security restrictions.
Below is a complete list of vulnerabilities:
- An use after free vulnerability in refresh driver timers can be exploited remotely to execute arbitrary code or cause denial of service;
- An use after free vulnerability in IndexedDB can be exploited remotely to execute arbitrary code or cause denial of service;
- An out-of-bounds write vulnerability in Mozilla Updater can be exploited remotely via malicious MAR file to execute arbitrary code or cause denial of service;
- Multiple memory corruptions vulnerabilities can be exploited remotely to execute arbitrary code.
Ursprüngliche Informationshinweise
CVE Liste
- CVE-2018-12377 critical
- CVE-2018-12378 critical
- CVE-2018-12379 critical
- CVE-2017-16541 critical
- CVE-2018-12381 critical
- CVE-2018-12382 critical
- CVE-2018-12383 critical
- CVE-2018-12375 critical
- CVE-2018-12376 critical
Mehr erfahren
Informieren Sie sich über die Statistiken der in Ihrer Region verbreiteten Sicherheitslücken statistics.securelist.com
Sie haben einen Fehler in der Beschreibung der Schwachstelle gefunden? Mitteilen!