Descripción
Multiple vulnerabilities were found in Mozilla Thunderbird. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service, execute arbitrary code.
Below is a complete list of vulnerabilities:
- Incorrect temporary files access configuration of Mozilla updater service can be exploited locally to bypass security restrictions;
- Use-after-free vulnerability in DocShell can be exploited remotely via specially designed website to cause denial of service;
- Use-after-free vulnerability in worker destruction can be exploited remotely via specially designed website to cause denial of service;
- Stack corruption due to incorrect number of arguments in WebRTC code can be exploited remotely via specially designed website to cause denial of service;
- Race condition vulnerability in Resist Fingerprinting can be exploited remotely via specially designed website to cause denial of service;
- Out of bounds write vulnerability in NSS can be exploited remotely via specially designed website to cause denial of service;
- Buffer overflow vulnerability in plain Firefox text serializer can be exploited remotely via specially designed website to cause denial of service;
Notas informativas originales
Explotación
Public exploits exist for this vulnerability.
Productos relacionados
Lista CVE
- CVE-2019-17012 critical
- CVE-2019-17010 critical
- CVE-2019-13722 high
- CVE-2019-17009 critical
- CVE-2019-17011 critical
- CVE-2019-17005 critical
- CVE-2019-17008 critical
- CVE-2019-11745 critical
Leer más
Conozca las estadísticas de las vulnerabilidades que se propagan en su región statistics.securelist.com
¿Has encontrado algún error en la descripción de esta vulnerabilidad? ¡Háznoslo saber!