Skip to main content

Mozilla Firefox Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 11 Sep 2009 4425 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in Mozilla Firefox, which could be exploited by attackers to manipulate certain data, bypass security restrictions or compromise a vulnerable system.

1. Memory corruption errors in the JavaScript and browser engines when parsing malformed data, which could be exploited by attackers to crash a vulnerable browser or execute arbitrary code.

2. Due to the browser displaying insufficient warnings when security modules are added or removed via "pkcs11.addmodule" or "pkcs11.deletemodule", which could allow an attacker to entice a user to install a malicious PKCS11 module and affect the cryptographic integrity of a vulnerable browser.

3. Due to a dangling pointer when manipulating columns of a XUL tree element, which could lead to arbitrary code execution.

4. Due to the default Windows font used to render the location bar and other text fields improperly displaying certain Unicode characters with tall line-height, which could be exploited to spoof the URL displayed in the location bar.

5. An error within the processing of BrowserFeedWriter objects, which could allow attackers to cause FeedWriter to execute arbitrary code with chrome privileges.