Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.800846
Categoría:Buffer overflow
Título:Mozilla Firefox Buffer Overflow Vulnerability - July09 (Windows)
Resumen:The host is installed with Mozilla Firefox browser and is prone; to Buffer Overflow vulnerability.
Descripción:Summary:
The host is installed with Mozilla Firefox browser and is prone
to Buffer Overflow vulnerability.

Vulnerability Insight:
- A NULL pointer dereference error exists due an unspecified vectors, related
to a 'flash bug.' which can cause application crash.

- Stack-based buffer overflow error is caused by sending an overly long string
argument to the 'document.write' method.

Vulnerability Impact:
Successful attacks will let attackers to can cause Denial of Service to the
legitimate user.

Affected Software/OS:
Firefox version 3.5.1 and prior on Windows

Solution:
Upgrade to Firefox version 3.6.3 or later.

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Referencia Cruzada: BugTraq ID: 35707
Common Vulnerability Exposure (CVE) ID: CVE-2009-2478
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00909.html
Common Vulnerability Exposure (CVE) ID: CVE-2009-2479
http://www.securityfocus.com/bid/35707
Bugtraq: 20090719 DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome (Google Search)
http://www.securityfocus.com/archive/1/505092/100/0/threaded
http://www.exploit-db.com/exploits/9158
http://websecurity.com.ua/3338/
https://bugzilla.mozilla.org/show_bug.cgi?id=504343
http://osvdb.org/55931
http://www.securitytracker.com/id?1022580
XForce ISS Database: firefox-unicode-data-dos(51729)
https://exchange.xforce.ibmcloud.com/vulnerabilities/51729
CopyrightCopyright (C) 2009 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.