Summary
This host is installed with Mozilla Firefox and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow attackers to inject scripts, bypass certain security restrictions, execute arbitrary code in the context of the browser.
Impact Level: System/Application
Solution
Upgrade to Mozilla Firefox version 15.0 or later,
For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Insight
- An error due to improper restriction of navigation to the about:newtab page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers creation of a new tab and then a new window.
- An error in the debugger in the developer-tools subsystem fails to restrict access to the remote-debugging service when remote debugging is disabled and the experimental HTTPMonitor extension has been installed and enabled.
Affected
Mozilla Firefox version before 15.0 on Windows
References
Severity
Classification
-
CVE CVE-2012-3965, CVE-2012-3973 -
CVSS Base Score: 9.3
AV:N/AC:M/Au:N/C:C/I:C/A:C
Related Vulnerabilities