Monday Dec 10, 2012

Multiple vulnerabilities in Mozilla Firefox

CVE DescriptionCVSSv2 Base ScoreComponentProduct and Resolution
CVE-2011-2372 Permissions, Privileges, and Access Controls vulnerability 3.5 Firefox web browser
Solaris 10 SPARC: 145080-12 X86: 145081-11
Solaris 11 11/11 SRU 3
CVE-2011-2995 Denial of Service (DoS) vulnerability 10.0
CVE-2011-2997 Denial of Service (DoS) vulnerability 10.0
CVE-2011-3000 Improper Control of Generation of Code ('Code Injection') vulnerability 4.3
CVE-2011-3001 Permissions, Privileges, and Access Controls vulnerability 4.3
CVE-2011-3002 Denial of Service (DoS) vulnerability 9.3
CVE-2011-3003 Denial of Service (DoS) vulnerability 10.0
CVE-2011-3004 Improper Input Validation vulnerability 4.3
CVE-2011-3005 Denial of Service (DoS) vulnerability 9.3
CVE-2011-3232 Improper Control of Generation of Code ('Code Injection') vulnerability 9.3
CVE-2011-3648 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability 4.3
CVE-2011-3650 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability 9.3
CVE-2011-3651 Denial of Service (DoS) vulnerability 10.0
CVE-2011-3652 Denial of Service (DoS) vulnerability 10.0
CVE-2011-3654 Denial of Service (DoS) vulnerability 10.0
CVE-2011-3655 Improper Control of Generation of Code ('Code Injection') vulnerability 9.3

This notification describes vulnerabilities fixed in third-party components that are included in Oracle's product distributions.
Information about vulnerabilities affecting Oracle products can be found on Oracle Critical Patch Updates and Security Alerts page.

About

This blog provides security vulnerability fix notifications relevant to third party software components distributed and supported as part of Oracle Products.
Summarized version of this blog is available as a mapping of CVEs and solutions.

Search

Archives
« December 2012 »
SunMonTueWedThuFriSat
      
1
2
3
5
6
7
8
9
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
     
Today