| a SkeyMedia Network site
A Honda & Acura Forum and technical discussion board. Topics include hybrid and swap information, turbo installation, tuning, ecu chipping, jdm parts and accessories, suspension setups and much more. Join us at HondaSwap.com
|
|||||||
|
Welcome, Guest! Please Register or Login:
Members have access to more features, better search, and see fewer ads! It's free, what are you waiting for? |
|
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 |
|
aliv dod
Join Date: Jul 2003
Location: Bristol, Ct.
Age: 28
Posts: 4,353
iTrader: 0 / 0%
Ride: A carriage
Rep Power: 99
![]() ![]() ![]() ![]() ![]() |
[img]style_emoticons/<#EMO_DIR#>/poke.gif[/img]
DESCRIPTION: Multiple vulnerabilities have been reported in Firefox, which can be exploited by malicious people to conduct cross-site scripting and phishing attacks, bypass certain security restrictions, disclose sensitive information, and potentially compromise a user's system. 1) An error exists where JavaScript can be injected into another page, which is currently loading. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site. 2) An error in the garbage collection in the JavaScript engine can be exploited to cause a memory corruption. Successful exploitation may allow execution of arbitrary code. 3) A boundary error in the CSS border rendering implementation may be exploited to write past the end of an array. 4) An integer overflow in the handling of overly long regular expressions in JavaScript may be exploited to execute arbitrary JavaScript bytecode. 5) Two errors in the handling of "-moz-grid" and "-moz-grid-group" display styles may be exploited to execute arbitrary code. 6) An error in the "InstallTrigger.install()" method can be exploited to cause a memory corruption. 7) An unspecified error can be exploited to spoof the secure lock icon and the address bar by changing the location of a pop-up window in certain situations. Successful exploitation requires that the "Entering secure site" dialog has been enabled (not enabled by default). 8) It is possible to trick users into downloading malicious files via the "Save image as..." menu option. 9) A JavaScript function created via an "eval()" call associated with a method of an XBL binding may be compiled with incorrect privileges. This can be exploited to execute arbitrary code. 10) An error where the "Object.watch()" method exposes the internal "clone parent" function object can be exploited to execute arbitrary JavaScript code with escalated privileges. Successful exploitation allows execution of arbitrary code. 11) An error in the protection of the compilation scope of built-in privileged XBL bindings can be exploited to execute arbitrary JavaScript code with escalated privileges. Successful exploitation allows execution of arbitrary code. 12) An unspecified error can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site via the window.controllers array. 13) An error in the processing of a certain sequence of HTML tags can be exploited to cause a memory corruption. Successful exploitation allows execution of arbitrary code. 14) An error in the "valueOf.call()" and "valueOf.apply()" methods can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an arbitrary site. 15) Some errors in the DHTML implementation can be exploited to cause a memory corruption. Successful exploitation may allow execution of arbitrary code. 16) An integer overflow error in the processing of the CSS letter-spacing property can be exploited to cause a heap-based buffer overflow. Successful exploitation allows execution of arbitrary code. 17) An error in the handling of file upload controls can be exploited to upload arbitrary files from a user's system by e.g. dynamically changing a text input box to a file upload control. 18) An unspecified error in the "crypto.generateCRMFRequest()" method can be exploited to execute arbitrary code. 19) An error in the handling of scripts in XBL controls can be exploited to gain chrome privileges via the "Print Preview" functionality. 20) An error in a security check in the "js_ValueToFunctionObject()" method can be exploited to execute arbitrary code via "setTimeout()" and "ForEach". 21) An error in the interaction between XUL content windows and the history mechanism can be exploited to trick users into interacting with a browser user interface which is not visible. Successful exploitation may allow execution of arbitrary code. __________________
kthx ©2003-2099 SiSteve Productions The person below me is gay.
|
|
|
|
|
|
#2 |
|
RETIRED
|
most of those are old.
in fact, 1.5.0.2 came out last night. i bet all of those flaws are patched. http://www.mozilla.org/projects/security/k...#firefox1.5.0.2 |
|
|
|
|
|
#3 |
|
I made the millionth post
Join Date: Jan 2005
Location: P R O V I D E N C E
Age: 31
Posts: 2,676
iTrader: 0 / 0%
Ride: 03 350z, 08 135i, 02 Excursion, 91 CRX Si, 91 Galant VR4, 86 CRX Si
Rep Power: 74
![]() ![]() ![]() |
yeah, I got the update this morning
__________________
Hold it fellas. I'm afraid you're just too darn loud. Next please. BRING THE NEXT GROUP PLEASE. |
|
|
|
|
|
#4 |
|
Senior Member
Join Date: Oct 2003
Location: South Eastern, WA
Age: 23
Posts: 3,545
iTrader: 0 / 0%
Ride: 1991 CRX DX/ Blacktop ZC 5spd Swap
Rep Power: 251
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Last night i got it pushed to me, installed and updated it self with no problems at all.
__________________
XBL GT: Churched V2 H3, CoD 4, CoD: WaW, Forza 2, H3: ODST, CoD 4: MW 2 МОΛΏΝ ΛΑΒΈ |
|
|
|