Kaspersky ID:
KLA10525
Detect Date:
03/31/2015
Updated:
09/26/2023

Description

Multiple serious vulnerabilities have been found in Mozilla Firefox before 37.0, Mozilla Firefox ESR 31.x before 31.6, Mozilla Thunderbird before 31.6. Malicious users can exploit these vulnerabilities to execute arbitrary code, cause a denial of service (heap memory corruption) and bypass an intended user-confirmation requirement.

Below is a complete list of vulnerabilities

  1. Improper resource:URLs restrictions, which can lead to execution arbitrary JavaScript code to bypass the Same Origin Policy;
  2. Multiple unspecified vulnerabilities in the browser engine can be exploited via unknown vectors;
  3. Lack of HTTPS session enforcement for lightweight theme add-on installations in Mozilla Firefox before 37.0 can lead to man-in-the-middle attacks;
  4. The QCMS implementation in Mozilla Firefox can be exploited via an image that is improperly handled during transformation;
  5. The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 can be exploited via unspecified vectors;
  6. The navigator.sendBeacon implementation can be exploited via a crafted web site;
  7. The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 can be exploited via vectors that trigger rendering of 2D graphics content;
  8. The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 can be exploited via a crafted HTML document containing a SOURCE element.

Original advisories

Exploitation

Public exploits exist for this vulnerability.

Related products

CVE list

  • CVE-2015-0812
    warning
  • CVE-2015-0813
    high
  • CVE-2015-0810
    warning
  • CVE-2015-0811
    high
  • CVE-2015-0815
    critical
  • CVE-2015-0814
    critical
  • CVE-2015-0805
    critical
  • CVE-2015-0806
    critical
  • CVE-2015-0804
    critical
  • CVE-2015-0816
    critical
  • CVE-2015-0807
    high
  • CVE-2015-0808
    critical

Read more

Find out the statistics of the vulnerabilities spreading in your region on statistics.securelist.com

Found an inaccuracy in the description of this vulnerability? Let us know!
Kaspersky Next
Let’s go Next: redefine your business’s cybersecurity
Learn more
New Kaspersky!
Your digital life deserves complete protection!
Learn more
Confirm changes?
Your message has been sent successfully.