KLA12149
Multiple vulnerabilities in Mozilla Firefox

Обновлено: 27/05/2021
Дата обнаружения
19/04/2021
Уровень угрозы
High
Описание

Multiple vulnerabilities were found in Mozilla Firefox. Malicious users can exploit these vulnerabilities to spoof user interface, execute arbitrary code, cause denial of service, bypass security restrictions, obtain sensitive information, gain privileges.

Below is a complete list of vulnerabilities:

  1. A vulnerability in 3D CSS can be exploited to spoof user interface;
  2. A memory corruption vulnerability can be exploited to execute arbitrary code;
  3. Memory corruption and vulnerability can be exploited to cause denial of service;
  4. A vulnerability related to session history can be exploited to security bypass restrictions;
  5. A integer overflow vulnerability can be exploited to security bypass restrictions;
  6. A race condition vulnerability in requestPointerLock() can be exploited to obtain sensitive information;
  7. A use-after-free vulnerability can be exploited to execute arbitrary code;
  8. A Null read vulnerability related to WebAssembly JIT can be exploited to cause denial of service;
  9. A vulnerability related to secure lock icon can be exploited to spoof user interface;
  10. A HTML injection vulnerability can be exploited to execute arbitrary code;
  11. A vulnerability related to FTP URL can be exploited to execute arbitrary code;
  12. A memory safety vulnerability related to Responsive Design Mode can be exploited to execute arbitrary code;
  13. Elevation of privilege vulnerability related to Blob URL can be exploited to gain privileges;
Пораженные продукты

Mozilla Firefox earlier than 88

Решение

Update to the latest version
Download Firefox

Первичный источник обнаружения
mfsa2021-16
Оказываемое влияние
?
ACE 
[?]

OSI 
[?]

DoS 
[?]

SB 
[?]

PE 
[?]

SUI 
[?]
Связанные продукты
Mozilla Firefox
CVE-IDS
KB list

5003209
5003197
5003174
5003208
5003171
5003172
5003169
5003173
5003203
5003220

Узнай статистику распространения уязвимостей в твоем регионе