Title: RETIRED: Mozilla Firefox and SeaMonkey MFSA 2009-65 through -71 Multiple Vulnerabilities
Severity: HIGH
Description:
The Mozilla Foundation has released multiple advisories to address vulnerabilities in Firefox and SeaMonkey.
NOTE: This BID is being retired; the following individual records now document these issues:
37361 Mozilla Firefox CVE-2009-3979 Multiple Remote Memory Corruption Vulnerabilities
37362 Mozilla Firefox CVE-2009-3980 Multiple Remote Memory Corruption Vulnerabilities
37363 Mozilla Firefox CVE-2009-3981 Remote Memory Corruption Vulnerability
37364 Mozilla Firefox CVE-2009-3982 JavaScript Engine Multiple Remote Memory Corruption Vulnerabilities
37369 Mozilla Firefox and SeaMonkey 'liboggplay' Media Library Remote Memory Corruption Vulnerabilities
37368 Mozilla Firefox and SeaMonkey Theora Video Library Remote Integer Overflow Vulnerability
37366 Mozilla Firefox and SeaMonkey NTLM Credential Reflection Authentication Bypass Vulnerability
37367 Mozilla Firefox and Sea Monkey Insecure Protocol Location Bar Spoofing Vulnerability
37370 Mozilla Firefox and Sea Monkey Content Injection Spoofing Vulnerability
37365 Mozilla Firefox 'window.opener' Property Chrome Privilege Escalation Vulnerability
37360 Mozilla Firefox/SeaMonkey GeckoActiveXObject Exception Message COM Object Enumeration Vulnerability
Affected Products:
- Mozilla Firefox 3.0.1
- Mozilla Firefox 3.0.10
- Mozilla Firefox 3.0.11
- Mozilla Firefox 3.0.12
- Mozilla Firefox 3.0.13
- Mozilla Firefox 3.0.14
- Mozilla Firefox 3.0.15
- Mozilla Firefox 3.0.2
- Mozilla Firefox 3.0.3
- Mozilla Firefox 3.0.4
- Mozilla Firefox 3.0.5
- Mozilla Firefox 3.0.6
- Mozilla Firefox 3.0.7
- Mozilla Firefox 3.0.7 Beta
- Mozilla Firefox 3.0.8
- Mozilla Firefox 3.0.9
- Mozilla Firefox 3.5.0
- Mozilla Firefox 3.5.1
- Mozilla Firefox 3.5.2
- Mozilla Firefox 3.5.3
- Mozilla Firefox 3.5.4
- Mozilla Firefox 3.5.5
- Mozilla SeaMonkey 1.0
- Mozilla SeaMonkey 1.0 dev
- Mozilla SeaMonkey 1.0.1
- Mozilla SeaMonkey 1.0.2
- Mozilla SeaMonkey 1.0.3
- Mozilla SeaMonkey 1.0.5
- Mozilla SeaMonkey 1.0.6
- Mozilla SeaMonkey 1.0.7
- Mozilla SeaMonkey 1.0.8
- Mozilla SeaMonkey 1.0.9
- Mozilla SeaMonkey 1.0.99
- Mozilla SeaMonkey 1.1 beta
- Mozilla SeaMonkey 1.1.1
- Mozilla SeaMonkey 1.1.10
- Mozilla SeaMonkey 1.1.11
- Mozilla SeaMonkey 1.1.12
- Mozilla SeaMonkey 1.1.13
- Mozilla SeaMonkey 1.1.14
- Mozilla SeaMonkey 1.1.15
- Mozilla SeaMonkey 1.1.15
- Mozilla SeaMonkey 1.1.16
- Mozilla SeaMonkey 1.1.17
- Mozilla SeaMonkey 1.1.2
- Mozilla SeaMonkey 1.1.3
- Mozilla SeaMonkey 1.1.4
- Mozilla SeaMonkey 1.1.5
- Mozilla SeaMonkey 1.1.6
- Mozilla SeaMonkey 1.1.7
- Mozilla SeaMonkey 1.1.8
- Mozilla SeaMonkey 1.1.9
- Mozilla SeaMonkey 2.0
- RedHat Desktop 3.0.0
- RedHat Enterprise Linux 5 server
- RedHat Enterprise Linux AS 3
- RedHat Enterprise Linux AS 4
- RedHat Enterprise Linux Desktop 5 client
- RedHat Enterprise Linux Desktop Workstation 5 client
- RedHat Enterprise Linux Desktop version 4
- RedHat Enterprise Linux ES 3
- RedHat Enterprise Linux ES 4
- RedHat Enterprise Linux WS 3
- RedHat Enterprise Linux WS 4
References:
- CVE: CVE-2009-3979
- CVE: CVE-2009-3980
- CVE: CVE-2009-3981
- CVE: CVE-2009-3982
- Mozilla: Fixed in Firefox 3.5.6
- Mozilla: MFSA 2009-65 Crashes with evidence of memory corruption (rv:1.9.1.6/ 1.9.0.16)
- Mozilla: MFSA 2009-66 Memory safety fixes in liboggplay media library
- Mozilla: MFSA 2009-67 Integer overflow, crash in libtheora video library
- Mozilla: MFSA 2009-68 NTLM reflection vulnerability
- Mozilla: MFSA 2009-69 Location bar spoofing vulnerabilities
- Mozilla: MFSA 2009-70 Privilege escalation via chrome window.opener
- Mozilla: MFSA 2009-71 GeckoActiveXObject exception messages can be used to enumerate inst
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.