Weekly Vulnerabilities Reports > March 17 to 23, 2014

Overview

12 new vulnerabilities reported during this period, including 5 critical vulnerabilities and 4 high severity vulnerabilities. This weekly summary report vulnerabilities in 21 products from 10 vendors including Mozilla, Suse, Opensuse, Redhat, and Canonical. Vulnerabilities are notably categorized as "Improper Privilege Management", "Out-of-bounds Write", "Out-of-bounds Read", "Permissions, Privileges, and Access Controls", and "Information Exposure".

  • 11 reported vulnerabilities are remotely exploitables.
  • 1 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 11 reported vulnerabilities are exploitable by an anonymous user.
  • Mozilla has the most reported vulnerabilities, with 10 reported vulnerabilities.
  • Debian has the most reported critical vulnerabilities, with 5 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

5 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2014-03-19 CVE-2014-1514 Mozilla
Debian
Opensuse
Suse
Redhat
Canonical
Out-of-bounds Write vulnerability in multiple products

vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by triggering incorrect use of the TypedArrayObject class.

9.8
2014-03-19 CVE-2014-1511 Mozilla
Canonical
Debian
Redhat
Opensuse
Suse
Improper Privilege Management vulnerability in multiple products

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.

9.8
2014-03-19 CVE-2014-1510 Mozilla
Canonical
Debian
Redhat
Opensuse
Suse
Improper Privilege Management vulnerability in multiple products

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.

9.8
2014-03-19 CVE-2014-1493 Mozilla
Canonical
Debian
Redhat
Opensuse
Suse
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

9.8
2014-03-19 CVE-2014-1508 Mozilla
Redhat
Debian
Canonical
Opensuse
Suse
Out-of-bounds Read vulnerability in multiple products

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.

9.1

4 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2014-03-19 CVE-2014-1513 Mozilla
Debian
Opensuse
Suse
Redhat
Canonical
Out-of-bounds Write vulnerability in multiple products

TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based out-of-bounds write or read) via a crafted web site.

8.8
2014-03-19 CVE-2014-1509 Mozilla
Redhat
Canonical
Opensuse
Suse
Classic Buffer Overflow vulnerability in multiple products

Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.

8.8
2014-03-19 CVE-2014-1497 Mozilla
Debian
Opensuse
Suse
Canonical
Redhat
Out-of-bounds Read vulnerability in multiple products

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process heap memory, cause a denial of service (out-of-bounds read and application crash), or possibly have unspecified other impact via a crafted WAV file.

8.8
2014-03-19 CVE-2014-1505 Mozilla
Canonical
Debian
Redhat
Opensuse
Suse
Novell
Information Exposure vulnerability in multiple products

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.

7.5

3 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2014-03-19 CVE-2014-2120 Cisco Cross-site Scripting vulnerability in Cisco Adaptive Security Appliance Software

Cross-site scripting (XSS) vulnerability in the WebVPN login page in Cisco Adaptive Security Appliance (ASA) Software allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCun19025.

6.1
2014-03-19 CVE-2014-1496 Mozilla
Suse
Improper Privilege Management vulnerability in multiple products

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 might allow local users to gain privileges by modifying the extracted Mar contents during an update.

5.5
2014-03-18 CVE-2014-2532 Oracle
Openbsd
Permissions, Privileges, and Access Controls vulnerability in multiple products

sshd in OpenSSH before 6.6 does not properly support wildcards on AcceptEnv lines in sshd_config, which allows remote attackers to bypass intended environment restrictions by using a substring located before a wildcard character.

4.9

0 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS