VRDA Feed by JPCERT/CC
  Vulnerability Response Decision Assistance Feed : Information for vulnerability impact analysis
[ about VRDA Feed | JPCERT/CC



 
Vulnerability Analysis Result (Revision No : 1) [ Download XML
VRDA-100219-002
Firefox Updates for Multiple Vulnerabilities
http://www.mozilla-japan.org/security/known-vulnerabilities/firefox35.html#firefox3.5.8

Firefox 3.5.8 で修正済み。MFSA 2010-05:SVG ドキュメントとバイナリ Content-Type の使用による XSS。MFSA 2010-04:window.dialogArguments がクロスドメインで読み取り可能なことによる XSS。MFSA 2010-03:HTML パーサの誤ったメモリ解放によるクラッシュ。MFSA 2010-02:Web ワーカーの配列処理におけるヒープ破損。MFSA 2010-01:メモリ破壊の形跡があるクラッシュ (rv:1.9.1.8/1.9.0.18)




About This Analysis Information
Analysis Information Provider:
JPCERT/CC
First Published:
2010-02-19
Source Information Category:
Advisory, Alert
Last Updated:
2010-02-19




Affected Product Tags
cpe:/a:mozilla:firefox     (Mozilla Firefox)
cpe:/a:mozilla:seamonkey     (Mozilla SeaMonkey)
cpe:/a:mozilla:thunderbird     (Mozilla Thunderbird)
 


Vulnerability Analysis Results
[Information Source Reliability] [?]
Low [?]

Medium [?]
X High [?]

[Impact Level] [?]
Low [?]

Low-Medium [?]
Medium-High [?]
X High [?]

[Access Required] [?]
Physical [?]

Local [?]
Non-routed [?]
X Routed [?]

[Authentication] [?]
Privileged [?]

Standard [?]
Limited [?]
X None or Unnecessary [?]

[User Interaction Required] [?]
Complex [?]

X Simple [?]
None [?]

[Technical Difficulty] [?]
High [?]

Medium-High [?]
Low-Medium [?]
Low [?]

[Availability of Remediation] [?]
X Official Patch [?]

Official Workaround [?]
Unofficial Patch [?]
None [?]

[Incident Activity] [?]
X None [?]

Exploit or PoC [?]
Activity Observed [?]

Alternatives




References
Common Vulnerabilities and Exposures (CVE) CVE-2009-1571




Common Vulnerabilities and Exposures (CVE) CVE-2009-3988




Common Vulnerabilities and Exposures (CVE) CVE-2010-0159




Common Vulnerabilities and Exposures (CVE) CVE-2010-0160




Common Vulnerabilities and Exposures (CVE) CVE-2010-0162





Copyright © 2010 JPCERT/CC All Rights Reserved.