Mozilla Firefox / Thunderbird Multiple Vulnerabilities
Last Update Date:
13 Jun 2014
Release Date:
12 Jun 2014
3664
Views
RISK: High Risk
TYPE: Clients - Browsers
Multiple vulnerabilities were identified in Mozilla Firefox / Thunderbird. A remote user can cause arbitrary code to be executed on the target user's system. A remote user can conduct clickjacking attacks.
- A remote user can create specially crafted content that, when loaded by the target user, will trigger a buffer overflow, use-after-free, memory corruption or boundary error and execute arbitrary code on the target system. The code will run with the privileges of the target user.
- On Windows 8 systems with a gamepad or virtual gamepad installed, a user can trigger a buffer overflow in the Gamepad API to execute arbitrary code.
- A remote user can create a specially crafted embedded flash object that, when loaded by the target user, will cause the cursor to be made invisible, facilitating clickjacking attacks.
Impact
- Denial of Service
- Remote Code Execution
- Data Manipulation
System / Technologies affected
- Firefox versions prior to 30.0
- Firefox ESR versions prior to 24.6
- Thunderbird versions prior to 24.6
Solutions
Before installation of the software, please visit the software manufacturer web-site for more details.
- The vendor has issued a fix (version 24.6, 30.0).
Vulnerability Identifier
- CVE-2014-1533
- CVE-2014-1534
- CVE-2014-1536
- CVE-2014-1537
- CVE-2014-1538
- CVE-2014-1539
- CVE-2014-1540
- CVE-2014-1541
- CVE-2014-1542
- CVE-2014-1543
Source
Related Link
Share with