Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.805248
Kategorie:General
Titel:Mozilla Firefox Multiple Vulnerabilities-01 Jan15 (Windows)
Zusammenfassung:This host is installed with Mozilla Firefox; and is prone to multiple vulnerabilities.
Beschreibung:Summary:
This host is installed with Mozilla Firefox
and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- Some unspecified errors.

- An error when rendering a bitmap image by the bitmap decoder within a
canvas element.

- An error when handling a request from 'navigator.sendBeacon' API interface
function.

- An error when handling a '407 Proxy Authentication' response with a
'Set-Cookie' header from a web proxy.

- A use-after-free error when handling tracks within WebRTC.

- An unspecified error related to the GMP (Gecko Media Plugin) sandbox.

- An error when handling the 'id-pkix-ocsp-nocheck' extension during
verification of a delegated OCSP (Online Certificate Status Protocol) response
signing certificate.

- An error when handling DOM (Document Object Model) objects with certain
properties.

- Improper restriction of timeline operations by the
'mozilla::dom::AudioParamTimeline::AudioNodeInputValue' function in the Web
Audio API.

Vulnerability Impact:
Successful exploitation will allow remote
attackers to disclose potentially sensitive information, bypass certain security
restrictions, and compromise a user's system.

Affected Software/OS:
Mozilla Firefox before version 35.0 on Windows

Solution:
Upgrade to Mozilla Firefox version 35.0
or later.

CVSS Score:
7.5

CVSS Vector:
AV:N/AC:L/Au:N/C:P/I:P/A:P

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2014-8643
BugTraq ID: 72043
http://www.securityfocus.com/bid/72043
http://www.securitytracker.com/id/1031533
http://secunia.com/advisories/62253
http://secunia.com/advisories/62446
SuSE Security Announcement: openSUSE-SU-2015:0077 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00014.html
SuSE Security Announcement: openSUSE-SU-2015:0192 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00002.html
XForce ISS Database: firefox-cve20148643-sec-bypass(99962)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99962
Common Vulnerability Exposure (CVE) ID: CVE-2014-8642
BugTraq ID: 72042
http://www.securityfocus.com/bid/72042
https://security.gentoo.org/glsa/201504-01
http://secunia.com/advisories/62242
http://secunia.com/advisories/62250
http://secunia.com/advisories/62316
http://secunia.com/advisories/62418
http://secunia.com/advisories/62790
XForce ISS Database: firefox-cve20148642-sec-bypass(99963)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99963
Common Vulnerability Exposure (CVE) ID: CVE-2014-8641
BugTraq ID: 72044
http://www.securityfocus.com/bid/72044
Debian Security Information: DSA-3127 (Google Search)
http://www.debian.org/security/2015/dsa-3127
RedHat Security Advisories: RHSA-2015:0046
http://rhn.redhat.com/errata/RHSA-2015-0046.html
http://secunia.com/advisories/62237
http://secunia.com/advisories/62273
http://secunia.com/advisories/62293
http://secunia.com/advisories/62313
SuSE Security Announcement: SUSE-SU-2015:0171 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00032.html
SuSE Security Announcement: SUSE-SU-2015:0173 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00033.html
SuSE Security Announcement: SUSE-SU-2015:0180 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-01/msg00036.html
XForce ISS Database: firefox-cve20148641-dos(99961)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99961
Common Vulnerability Exposure (CVE) ID: CVE-2014-8640
BugTraq ID: 72045
http://www.securityfocus.com/bid/72045
XForce ISS Database: firefox-cve20148640-info-disc(99960)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99960
Common Vulnerability Exposure (CVE) ID: CVE-2014-8639
BugTraq ID: 72046
http://www.securityfocus.com/bid/72046
Debian Security Information: DSA-3132 (Google Search)
http://www.debian.org/security/2015/dsa-3132
RedHat Security Advisories: RHSA-2015:0047
http://rhn.redhat.com/errata/RHSA-2015-0047.html
http://www.securitytracker.com/id/1031534
http://secunia.com/advisories/62259
http://secunia.com/advisories/62274
http://secunia.com/advisories/62283
http://secunia.com/advisories/62304
http://secunia.com/advisories/62315
http://secunia.com/advisories/62657
SuSE Security Announcement: openSUSE-SU-2015:0133 (Google Search)
http://lists.opensuse.org/opensuse-updates/2015-01/msg00071.html
SuSE Security Announcement: openSUSE-SU-2015:1266 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://www.ubuntu.com/usn/USN-2460-1
XForce ISS Database: firefox-cve20148639-session-hijacking(99959)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99959
Common Vulnerability Exposure (CVE) ID: CVE-2014-8638
BugTraq ID: 72047
http://www.securityfocus.com/bid/72047
XForce ISS Database: firefox-cve20148638-csrf(99958)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99958
Common Vulnerability Exposure (CVE) ID: CVE-2014-8637
BugTraq ID: 72048
http://www.securityfocus.com/bid/72048
XForce ISS Database: firefox-cve20148637-info-disc(99957)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99957
Common Vulnerability Exposure (CVE) ID: CVE-2014-8636
BugTraq ID: 72041
http://www.securityfocus.com/bid/72041
http://packetstormsecurity.com/files/130972/Firefox-Proxy-Prototype-Privileged-Javascript-Injection.html
https://community.rapid7.com/community/metasploit/blog/2015/03/23/r7-2015-04-disclosure-mozilla-firefox-proxy-prototype-rce-cve-2014-8636
XForce ISS Database: firefox-cve20148636-sec-bypass(99964)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99964
Common Vulnerability Exposure (CVE) ID: CVE-2014-8635
BugTraq ID: 72050
http://www.securityfocus.com/bid/72050
Common Vulnerability Exposure (CVE) ID: CVE-2014-8634
BugTraq ID: 72049
http://www.securityfocus.com/bid/72049
XForce ISS Database: firefox-cve20148634-code-exec(99955)
https://exchange.xforce.ibmcloud.com/vulnerabilities/99955
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.