Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.851459
Kategorie:SuSE Local Security Checks
Titel:openSUSE: Security Advisory for MozillaFirefox (openSUSE-SU-2016:3184-1)
Zusammenfassung:The remote host is missing an update for the 'MozillaFirefox'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'MozillaFirefox'
package(s) announced via the referenced advisory.

Vulnerability Insight:
This update to MozillaFirefox 50.1.0 fixes the following vulnerabilities:

- CVE-2016-9894: Buffer overflow in SkiaGL

- CVE-2016-9899: Use-after-free while manipulating DOM events and audio
elements

- CVE-2016-9895: CSP bypass using marquee tag

- CVE-2016-9896: Use-after-free with WebVR

- CVE-2016-9897: Memory corruption in libGLES

- CVE-2016-9898: Use-after-free in Editor while manipulating DOM subtrees

- CVE-2016-9900: Restricted external resources can be loaded by SVG images
through data URLs

- CVE-2016-9904: Cross-origin information leak in shared atoms

- CVE-2016-9901: Data from Pocket server improperly sanitized before
execution

- CVE-2016-9902: Pocket extension does not validate the origin of events

- CVE-2016-9903: XSS injection vulnerability in add-ons SDK

- CVE-2016-9080: Memory safety bugs fixed in Firefox 50.1

- CVE-2016-9893: Memory safety bugs fixed in Firefox 50.1 and Firefox ESR
45.6

The following bugs were fixed:

- boo#1011922: fix crash after a few seconds of usage on AArch64

Affected Software/OS:
MozillaFirefox on openSUSE Leap 42.1, openSUSE 13.2

Solution:
Please install the updated package(s).

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2016-9080
BugTraq ID: 94883
http://www.securityfocus.com/bid/94883
http://www.securitytracker.com/id/1037461
Common Vulnerability Exposure (CVE) ID: CVE-2016-9893
BugTraq ID: 94885
http://www.securityfocus.com/bid/94885
Debian Security Information: DSA-3757 (Google Search)
https://www.debian.org/security/2017/dsa-3757
https://security.gentoo.org/glsa/201701-15
RedHat Security Advisories: RHSA-2016:2946
http://rhn.redhat.com/errata/RHSA-2016-2946.html
RedHat Security Advisories: RHSA-2016:2973
http://rhn.redhat.com/errata/RHSA-2016-2973.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-9894
Common Vulnerability Exposure (CVE) ID: CVE-2016-9895
Common Vulnerability Exposure (CVE) ID: CVE-2016-9896
Common Vulnerability Exposure (CVE) ID: CVE-2016-9897
Common Vulnerability Exposure (CVE) ID: CVE-2016-9898
Common Vulnerability Exposure (CVE) ID: CVE-2016-9899
https://www.exploit-db.com/exploits/41042/
Common Vulnerability Exposure (CVE) ID: CVE-2016-9900
Common Vulnerability Exposure (CVE) ID: CVE-2016-9901
Common Vulnerability Exposure (CVE) ID: CVE-2016-9902
Common Vulnerability Exposure (CVE) ID: CVE-2016-9903
Common Vulnerability Exposure (CVE) ID: CVE-2016-9904
CopyrightCopyright (C) 2016 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.