FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

mozilla -- multiple vulnerabilities

Affected packages
firefox < 2.0.0.18,1
3.*,1 < firefox < 3.0.4,1
linux-firefox < 2.0.0.18
linux-seamonkey < 1.1.13
seamonkey < 1.1.13
linux-thunderbird < 2.0.0.18
thunderbird < 2.0.0.18

Details

VuXML ID f29fea8f-b19f-11dd-a55e-00163e000016
Discovery 2008-11-13
Entry 2008-11-13
Modified 2008-11-23

The Mozilla Foundation reports:

MFSA 2008-58 Parsing error in E4X default namespace

MFSA 2008-57 -moz-binding property bypasses security checks on codebase principals

MFSA 2008-56 nsXMLHttpRequest::NotifyEventListeners() same-origin violation

MFSA 2008-55 Crash and remote code execution in nsFrameManager

MFSA 2008-54 Buffer overflow in http-index-format parser

MFSA 2008-53 XSS and JavaScript privilege escalation via session restore

MFSA 2008-52 Crashes with evidence of memory corruption (rv:1.9.0.4/1.8.1.18)

MFSA 2008-51 file: URIs inherit chrome privileges when opened from chrome

MFSA 2008-50 Crash and remote code execution via __proto__ tampering

MFSA 2008-49 Arbitrary code execution via Flash Player dynamic module unloading

MFSA 2008-48 Image stealing via canvas and HTTP redirect

MFSA 2008-47 Information stealing via local shortcut files

MFSA 2008-46 Heap overflow when canceling newsgroup message

MFSA 2008-44 resource: traversal vulnerabilities

MFSA 2008-43 BOM characters stripped from JavaScript before execution

MFSA 2008-42 Crashes with evidence of memory corruption (rv:1.9.0.2/1.8.1.17)

MFSA 2008-41 Privilege escalation via XPCnativeWrapper pollution

MFSA 2008-38 nsXMLDocument::OnChannelRedirect() same-origin violation

MFSA 2008-37 UTF-8 URL stack buffer overflow

References

CVE Name CVE-2008-0017
CVE Name CVE-2008-4582
CVE Name CVE-2008-5012
CVE Name CVE-2008-5013
CVE Name CVE-2008-5014
CVE Name CVE-2008-5015
CVE Name CVE-2008-5016
CVE Name CVE-2008-5017
CVE Name CVE-2008-5018
CVE Name CVE-2008-5019
CVE Name CVE-2008-5021
CVE Name CVE-2008-5022
CVE Name CVE-2008-5023
CVE Name CVE-2008-5024
URL http://www.mozilla.org/security/announce/2008/mfsa2008-47.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-48.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-49.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-50.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-51.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-52.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-53.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-54.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-55.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-56.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-57.html
URL http://www.mozilla.org/security/announce/2008/mfsa2008-58.html