Summary
This host is installed with Mozilla Firefox
and is prone to multiple vulnerabilities.
Impact
Successful exploitation will allow attackers
disclose potentially sensitive information, bypass certain security restrictions, conduct denial-of-service attack and compromise a user's system.
Impact Level: System/Application
Solution
Upgrade to Mozilla Firefox version 33.0
or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html
Insight
Multiple flaws exist due to,
- An error in Alarm API which does not properly restrict toJSON calls.
- An error when handling video sharing within a WebRTC session running within an iframe.
- Multiple errors in the Public Key Pinning (PKP) implementation.
- An use-after-free error when handling text layout related to DirectionalityUtils.
- An error when repeatedly rendering a GIF image within a canvas element.
- An out-of-bounds error within the 'get_tile' function when buffering WebM format video containing frames.
- An out-of-bounds error within 'mozilla::dom::OscillatorNodeEngine::ComputeCustom' method when interacting with custom waveforms.
- An error within the 'nsTransformedTextRun' class when handling capitalization style changes during CSS parsing.
- An error when handling camera recording within an iframe related to site navigation.
- Other unspecified errors.
Affected
Mozilla Firefox before version 33.0 on Windows
Detection
Get the installed version with the help of
detect NVT and check the version is vulnerable or not.
References
- http://msisac.cisecurity.org/advisories/2014/2014-088.cfm
- http://osvdb.com/113159
- http://osvdb.com/113161
- http://secunia.com/advisories/59643/
- https://www.mozilla.org/security/announce/2014/mfsa2014-76.html
- https://www.mozilla.org/security/announce/2014/mfsa2014-81.html
- https://www.mozilla.org/security/announce/2014/mfsa2014-82.html
Updated on 2017-03-28
Severity
Classification
-
CVE CVE-2014-1574, CVE-2014-1575, CVE-2014-1576, CVE-2014-1577, CVE-2014-1578, CVE-2014-1580, CVE-2014-1581, CVE-2014-1582, CVE-2014-1583, CVE-2014-1584, CVE-2014-1585, CVE-2014-1586 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Adobe Acrobat Multiple Vulnerabilities - Mac OS X
- Adobe Flash Player Arbitrary Code Execution Vulnerability - 01 Feb14 (Mac OX S)
- Adobe AIR Multiple Vulnerabilities -02 April 13 (Mac OS X)
- Adobe Acrobat Multiple Vulnerabilities - 01 Jan14 (Windows)
- Adobe Acrobat Multiple Unspecified Vulnerabilities -01 Feb13 (Windows)