Oval Definition:oval:org.mitre.oval:tst:121380
Comment:Mozilla Firefox ESR version is less than 17.0.9 and greater than or equal to 17.x
Type:file_testNamespace:windows
Check_Existence:at_least_one_existsCheck:all
State Operator:AND
References
Object:oval:org.mitre.oval:obj:30347
State:oval:org.mitre.oval:ste:32562
State:oval:org.mitre.oval:ste:33216
Referencing Definitions
Definition IDClassTitleLast Modified
oval:org.mitre.oval:def:18443
V
Use-after-free vulnerability in the mozilla::layout::ScrollbarActivity function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via vectors related to image-document scrolling.
2014-10-06
oval:org.mitre.oval:def:18520
V
Buffer overflow in the nsFloatManager::GetFlowArea function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code via crafted use of lists and floats within a multi-column layout.
2014-10-06
oval:org.mitre.oval:def:18789
V
Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not properly identify the thisobject during use of user-defined getter methods on DOM proxies, which might allow remote attackers to bypass intended access restrictions via vectors involving an expando object.
2014-10-06
oval:org.mitre.oval:def:18821
V
Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.
2014-10-06
oval:org.mitre.oval:def:18856
V
The nsGfxScrollFrameInner::IsLTR function in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to improperly establishing parent-child relationships of range-request nodes.
2014-10-06
BACK