KLA10464
Multiple vulnerabilities in Mozilla products
Updated: 06/01/2019
Detect date
?
02/24/2015
Severity
?
Critical
Description

Multiple serious vulnerabilities have been found in Mozilla products. Malicious users can exploit these vulnerabilities to cause denial of service, gain privilleges, obtain sensitiv information, execute arbitrary code, spoof user interface or read local files.

Below is a complete list of vulnerabilities

  1. An unspecified vulnerabilities can be exploited remotely via unknown vectors;
  2. Buffer overflow can be exploited remotely via a specially designed MP3 file, MP4 file or SVG graphics;
  3. An use-after-free vulnerability can be exploited remotely via specially designed content and other unknown vectors;
  4. Improper domain name recognition can be exploited remotely via a specially designed URL;
  5. An untrusted path vulnerability can be exploited locally via DLL hijack;
  6. Improper memory allocation can be exploited remotely via a specially designed WebGL content;
  7. An unspecified vulnerability can be exploited remotely via unknown vectors;
  8. Unknown vulnerability related to form autocompletion can be exploited remotely via a specially designed JavaScript;
  9. A double free vulnerability can be exploited remotely via specially designed JavaScript;
  10. An unknwon vulnerability can be exploited remotely via a specially designed CSS;
  11. Lack of API restrictions can be exploited remotely via vectirs related to UITour;
  12. Lack of transaction restrictions and other unknown vulnerabilities can be exploited remotely via specially designed web site;
Affected products

Mozilla Firefox versions earlier than 36
Mozilla Firefox ESR versions earlier than 31.5
Mozilla Thunderbird versions earlier than 31.5

Solution

Update to latest version!

Original advisories

MFSA 2015-11 — 2015-27

Impacts
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

RLF 
[?]

SUI 
[?]
Related products
Mozilla Firefox
Mozilla Thunderbird
CVE-IDS
?
CVE-2015-08237.5Critical
CVE-2015-08286.8High
CVE-2015-08344.3Warning
CVE-2015-08357.5Critical
CVE-2015-08367.5Critical
CVE-2015-08254.3Warning
CVE-2015-08316.8High
CVE-2015-08305.0Critical
CVE-2015-08245.0Critical
CVE-2015-08274.3Warning
CVE-2015-08296.8High
CVE-2015-08224.3Warning
CVE-2015-08336.9High
CVE-2015-08266.8High
CVE-2015-08202.6Warning
CVE-2015-08325.0Critical
CVE-2015-08216.8High
CVE-2015-08194.3Warning