Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
ID: db61d53b-724d-5e40-bf78-a1d264ff7da5
STIX ID: report--db61d53b-724d-5e40-bf78-a1d264ff7da5
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities affecting Mozilla products were disclosed (several CVEs). The most severe issues are memory-safety bugs and sandbox-escape flaws (including use-after-free and invalid pointer/undefined behavior) that Mozilla indicates could lead to arbitrary code execution; these could be exploited via drive-by compromise. The advisory also lists several lower-severity flaws (same-origin bypass, integer overflow, information disclosure, spoofing, mitigation bypass) across various components and platforms; successful exploitation could allow installation of programs, data access/modification, or creation of accounts depending on user privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
