10.16.09 - 09:00pm
Mike Shaver, Mozilla’s Vice President of Engineering writes:
I’ve previously posted about the .NET Framework Assistant add-on that was delivered via Windows Update earlier this year. It’s recently surfaced that it has a serious security vulnerability, and Microsoft is recommending that all users disable the add-on.
Because of the difficulties some users have had entirely removing [...]
Category: Security, Vulnerabilities | | 82 Comments »
07.28.09 - 03:40pm
Issue
The URL in the address bar can be spoofed when a new window or tab is opened by a malicious web page.
Impact to users
If a user visits a page hosting this malicious code, a new window or tab can be opened with a faked URL. There is no way of determining if the URL is [...]
Category: Firefox, Security, Vulnerabilities | | 15 Comments »
07.19.09 - 02:44pm
In the last few days, there have been several reports (including one via SANS) of a bug in Firefox related to handling of certain very long Unicode strings. While these strings can result in crashes of some versions of Firefox, the reports by press and various security agencies have incorrectly indicated that this is [...]
Category: Firefox, Security, Vulnerabilities | | 16 Comments »
07.14.09 - 10:15am
Issue
A bug discovered last week in Firefox 3.5’s Just-in-time (JIT) JavaScript compiler was disclosed publicly yesterday. It is a critical vulnerability that can be used to execute malicious code.
Impact
The vulnerability can be exploited by an attacker who tricks a victim into viewing a malicious Web page containing the exploit code. The vulnerability can [...]
Category: Firefox, Security, Vulnerabilities | | 80 Comments »
03.26.09 - 01:55pm
Issue
The pwn2own bug that Nils discovered at CanSecWest 2009 and the XSLT vulnerability recently made public by Guido Landi (http://www.securityfocus.com/bid/34235) are both critical issues that can result in malicious code execution.
Impact
These issues can be exploited by tricking a user into visiting a malicious web page hosting the exploit code. The pwn2own bug can be [...]
Category: Firefox, Press, Security, Vulnerabilities | | 16 Comments »
12.15.08 - 02:48pm
There has been some interest in the last few days about a recent report from a company called Bit9 about application vulnerabilities. While we’re always happy to see stories that focus on educating our users about security, there are some problems with Bit9’s methodology that hinder its ability to draw any meaningful conclusions.
Bit9 says it [...]
Category: Firefox, Press, Security, Vulnerabilities | | Comments Off
07.30.08 - 12:30pm
Issue
A null pointer dereference in the content layout component of Firefox allows an attacker to crash the browser when a user navigates to a malicious page.
Impact
If a user browses to a malicious page that takes advantage of this vulnerability, the browser will crash. A feature in Firefox called Session Restore will restore the browser session [...]
Category: Firefox, Security, Vulnerabilities | | 15 Comments »
07.16.08 - 02:15pm
Issue
A vulnerability in the way Firefox handles CSS allows an attacker to take advantage of an integer overflow and execute arbitrary code. In order for the attack to be successful a user must browse to a malicious site. The advisory is available here.
Impact
This critical vulnerability was reported to Mozilla before details were available publicly. By [...]
Category: Firefox, Security, Vulnerabilities | | 6 Comments »
06.18.08 - 09:07pm
TippingPoint ZDI notified Mozilla of a vulnerability in Firefox that impacts versions 2.x and 3.0. This issue is currently under investigation. To protect our users, the details of the issue will remain closed until a patch is made available. There is no public exploit, the details are private, and so the current risk to users [...]
Category: Firefox, Security, Vulnerabilities | | 20 Comments »
05.12.08 - 02:16am
As today’s headlines confirm, there is still a lot of confusion about what happened to the Vietnamese language pack, who is impacted, and what that impact really is.
First of all, there is no virus in the Vietnamese language pack. Vietnamese language pack for Firefox users have not been infected with a virus. The remnant we [...]
Category: Firefox, Security, Vulnerabilities | | 4 Comments »