KLA10464
Multiple vulnerabilities in Mozilla products
Updated: 11/06/2018
CVSS
?
7.5
Detect date
?
02/24/2015
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in Mozilla products. Malicious users can exploit these vulnerabilities to cause denial of service, gain privilleges, obtain sensitiv information, execute arbitrary code, spoof user interface or read local files.

Below is a complete list of vulnerabilities

  1. An unspecified vulnerabilities can be exploited remotely via unknown vectors;
  2. Buffer overflow can be exploited remotely via a specially designed MP3 file, MP4 file or SVG graphics;
  3. An use-after-free vulnerability can be exploited remotely via specially designed content and other unknown vectors;
  4. Improper domain name recognition can be exploited remotely via a specially designed URL;
  5. An untrusted path vulnerability can be exploited locally via DLL hijack;
  6. Improper memory allocation can be exploited remotely via a specially designed WebGL content;
  7. An unspecified vulnerability can be exploited remotely via unknown vectors;
  8. Unknown vulnerability related to form autocompletion can be exploited remotely via a specially designed JavaScript;
  9. A double free vulnerability can be exploited remotely via specially designed JavaScript;
  10. An unknwon vulnerability can be exploited remotely via a specially designed CSS;
  11. Lack of API restrictions can be exploited remotely via vectirs related to UITour;
  12. Lack of transaction restrictions and other unknown vulnerabilities can be exploited remotely via specially designed web site;
Affected products

Mozilla Firefox versions earlier than 36
Mozilla Firefox ESR versions earlier than 31.5
Mozilla Thunderbird versions earlier than 31.5

Solution

Update to latest version!

Original advisories

MFSA 2015-11 — 2015-27

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

RLF 
[?]

SUI 
[?]
Related products
Mozilla Firefox
Mozilla Thunderbird
CVE-IDS
?

CVE-2015-0823
CVE-2015-0828
CVE-2015-0834
CVE-2015-0835
CVE-2015-0836
CVE-2015-0825
CVE-2015-0831
CVE-2015-0830
CVE-2015-0824
CVE-2015-0827
CVE-2015-0829
CVE-2015-0822
CVE-2015-0833
CVE-2015-0826
CVE-2015-0820
CVE-2015-0832
CVE-2015-0821
CVE-2015-0819