Skip to main content

Mozilla Firefox / Thunderbird Multiple Vulnerabilities

Last Update Date: 22 Jun 2011 14:33 Release Date: 22 Jun 2011 5727 Views

RISK: High Risk

TYPE: Clients - Browsers

TYPE: Browsers

Multiple vulnerabilities have been identified in Mozilla Firefox and Thunderbird, which can be exploited by malicious people to bypass certain security restrictions and compromise a vulnerable system.

  1. Some unspecified errors can be exploited to corrupt memory.
  2. A use-after-free error in the "nsSVGPathSegList::ReplaceItem()" method when processing SVG element lists can be exploited to access an invalid element list when a user supplied callback deletes an object.
  3. A use-after-free error in the "nsSVGPointList::AppendElement()" method when processing SVG element lists can be exploited to access an invalid element list when a user supplied callback deletes an object.
  4. A use-after-free error in "nsXULCommandDispatcher" when processing XUL documents can be exploited to remove the currently used command updater.
  5. An error when handling cookies for two domains where one contains a trailing dot character can be exploited to bypass the same-origin policy and disclose a cookie to a third party.