Mozilla Products Multiple Vulnerabilities January13 (Windows)

Summary
This host is installed with Mozilla Firefox/Thunderbird/Seamonkey and is prone to multiple vulnerabilities.
Impact
Successful exploitation could allow attackers to inject scripts, bypass certain security restrictions, execute arbitrary code or crash the application in the context of the browser. Impact Level: System/Application
Solution
Upgrade to Mozilla Firefox version 18.0 or ESR version 10.0.12 or 17.0.2 or later, For updates refer to http://www.mozilla.com/en-US/firefox/all.html Upgrade to SeaMonkey version to 2.15 or later, http://www.mozilla.org/projects/seamonkey/ Upgrade to Thunderbird version to 17.0.2 or ESR 10.0.12 or 17.0.2 or later, http://www.mozilla.org/en-US/thunderbird/
Insight
- URL spoofing in address bar during page loads in conjunction with a 204 (aka No Content) HTTP status code. - Improper interaction between plugin objects and SVG elements. - Use-after-free error exists within the implementation serializeToStream in the XMLSerializer component and ListenerManager, and in the function 'TableBackgroundPainter::TableBackgroundData::Destroy'. 'serializeToStream' implementation in the XMLSerializer component - Compartment mismatch with quickstubs returned values. - An error within the 'XBL.__proto__.toString()' can be exploited to disclose the address space layout.
Affected
SeaMonkey version before 2.15 on Windows Thunderbird version before 17.0.2 on Windows Mozilla Firefox version before 18.0 on Windows Thunderbird ESR version 10.x before 10.0.12 and 17.x before 17.0.2 on Windows Mozilla Firefox ESR version 10.x before 10.0.12 and 17.x before 17.0.2 on Windows
References