27.02.2013 Views

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

(PVS) Signatures - Tenable Network Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

CVE-2012-5354<br />

Mozilla Thunderbird 15.x <<br />

Passive Vulnerability Scanner (<strong>PVS</strong>) <strong>Signatures</strong><br />

<strong>PVS</strong> ID: 6604 FAMILY: SMTP Clients RISK: HIGH NESSUS ID:62582<br />

Description: Synopsis :\n\nThe remote host has a web browser installed that is vulnerable to multiple<br />

vulnerabilities.\n\nFor your information, the observed version of Firefox is : \n %L<br />

\n\nVersions of Firefox 16.x are potentially affected by the following security issues :\n\n -<br />

Multiple memory-corruption vulnerabilities in the browser engine that could lead to<br />

arbitrary code execution. (CVE-2012-3982, CVE-2012-3983, CVE-2012-4191)\n\n - A<br />

URI-spoofing vulnerability due to an error when handling the '' dropdown menu.<br />

This issue can be exploited to display arbitrary content while showing the URL of another<br />

site. An attacker can also exploit this issue to cause click jacking attacks. (CVE-2012-3984,<br />

CVE-2012-5354)\n\n - A security-bypass vulnerability exists because it fails to properly<br />

enforce the same-origin policy. Specifically, the error occurs when handling<br />

'document.domain'. An attacker can exploit this issue to execute cross-site scripting attacks.<br />

(CVE-2012-3985)\n\n - Multiple security bypass vulnerabilities exists in the<br />

'nsDOMWindowUtils' methods. (CVE-2012-3986)\n\n - A cross-site scripting vulnerability<br />

exists because it fails to sufficiently sanitize user-supplied input. Specifically, this issue<br />

occurs when transitioning into Reader Mode. Note: This issue affects only Firefox for<br />

Android. CVE-2012-3987)\n\n - A use-after-free issue occurs when invoking full screen<br />

mode and navigating backwards in history. (CVE-2012-3988)\n\n - A denial-of-service<br />

vulnerability that occurs due to invalid cast error. Specifically, this issue occurs when using<br />

the instanceof operator on certain JavaScript objects. (CVE-2012-3989)\n\n - A<br />

security-bypass vulnerability exists because it fails to properly enforce the cross-origin<br />

policy. Specifically, this issue occurs when invoking the 'GetProperty()' function through<br />

JSAPI. An attacker can exploit this issue to perform arbitrary code-execution.<br />

(CVE-2012-3991)\n\n - A cross-site scripting vulnerability exists because it fails to<br />

sufficiently sanitize user-supplied input. Specifically, this issue occurs when handling the<br />

'location' property through binary plugins. (CVE-2012-3994)\n\n - A security-bypass<br />

vulnerability exists because of an error in the Chrome Object Wrapper (COW) when<br />

handling the 'InstallTrigger' object. An attacker can exploit this issue to access certain<br />

privileged functions and properties. (CVE-2012-4184, CVE-2012-3993)\n\n - An arbitrary<br />

code-execution occurs when handling the 'location.hash' property and history navigation.<br />

(CVE-2012-3992)\n\n - An out-of-bounds read error affects the<br />

'IsCSSWordSpacingSpace()' function. (CVE-2012-3995)\n\n - A use-after-free error affects<br />

the 'nsHTMLCSSUtils::CreateCSSPropertyTxn()' function. (CVE-2012-4179)\n\n - A<br />

heap-based buffer-overflow vulnerability exists in the<br />

'nsHTMLEditor::IsPrevCharInNodeWhitespace()' function. (CVE-2012-4180)\n\n - A<br />

use-after-free error affects the 'nsSMILAnimationController::DoSample()' function.<br />

(CVE-2012-4181)\n\n - A use-after-free error affects the 'nsTextEditRules::WillInsert()'<br />

function. (CVE-2012-4182)\n\n - A use-after-free error affects the<br />

'DOMSVGTests::GetRequiredFeatures()' function. (CVE-2012-4183)\n\n - A<br />

buffer-overflow vulnerability exists in the 'nsCharTraits::length()' function.<br />

(CVE-2012-4185)\n\n - A heap-based buffer-overflow vulnerability exists in the<br />

'nsWaveReader::DecodeAudioData()" function. (CVE-2012-4186)\n\n - A<br />

memory-corruption vulnerability exists in the 'insPos' property. (CVE-2012-4187)\n\n - A<br />

heap-based buffer-overflow exists in the 'Convolve3x3()' function. (CVE-2012-4188)\n\n -<br />

A use-after-free error affects the 'nsIContent::GetNameSpaceID()' function.<br />

(CVE-2012-3990)\n\n - A cross domain information disclosure exists due to improper<br />

Family Internet Services 1811

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!