Weekly Vulnerabilities Reports > April 28 to May 4, 2014

Overview

7 new vulnerabilities reported during this period, including 2 critical vulnerabilities and 3 high severity vulnerabilities. This weekly summary report vulnerabilities in 16 products from 7 vendors including Debian, Fedoraproject, Opensuse, Mozilla, and Redhat. Vulnerabilities are notably categorized as "Use After Free", "Out-of-bounds Write", "Improper Privilege Management", "Cross-site Scripting", and "Classic Buffer Overflow".

  • 7 reported vulnerabilities are remotely exploitables.
  • 1 reported vulnerabilities are related to weaknesses in OWASP Top Ten.
  • 7 reported vulnerabilities are exploitable by an anonymous user.
  • Debian has the most reported vulnerabilities, with 7 reported vulnerabilities.
  • Debian has the most reported critical vulnerabilities, with 2 reported vulnerabilities.

TOTAL
VULNERABILITIES
CRITICAL RISK
VULNERABILITIES
HIGH RISK
VULNERABILITIES
MEDIUM RISK
VULNERABILITIES
LOW RISK
VULNERABILITIES
REMOTELY
EXPLOITABLE
LOCALLY
EXPLOITABLE
EXPLOIT
AVAILABLE
EXPLOITABLE
ANONYMOUSLY
AFFECTING
WEB APPLICATION

Vulnerability Details

The following table list reported vulnerabilities for the period covered by this report:

Expand/Hide

2 Critical Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2014-04-30 CVE-2014-1532 Mozilla
Fedoraproject
Canonical
Debian
Redhat
Opensuse
Suse
Use After Free vulnerability in multiple products

Use-after-free vulnerability in the nsHostResolver::ConditionallyRefreshRecord function in libxul.so in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors related to host resolution.

9.8
2014-04-30 CVE-2014-1524 Mozilla
Canonical
Debian
Redhat
Opensuse
Suse
Fedoraproject
Classic Buffer Overflow vulnerability in multiple products

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted JavaScript code that accesses a non-XBL object as if it were an XBL object.

9.8

3 High Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2014-04-30 CVE-2014-1531 Mozilla
Canonical
Debian
Redhat
Fedoraproject
Opensuse
Suse
Use After Free vulnerability in multiple products

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that is not properly handled during an image-resize operation.

8.8
2014-04-30 CVE-2014-1529 Mozilla
Canonical
Debian
Redhat
Fedoraproject
Opensuse
Suse
Improper Privilege Management vulnerability in multiple products

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.

8.8
2014-04-30 CVE-2014-1518 Mozilla
Fedoraproject
Canonical
Debian
Redhat
Opensuse
Suse
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
8.8

2 Medium Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS
2014-04-30 CVE-2014-1523 Mozilla
Fedoraproject
Debian
Canonical
Redhat
Opensuse
Suse
Out-of-bounds Write vulnerability in multiple products

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

6.5
2014-04-30 CVE-2014-1530 Mozilla
Fedoraproject
Canonical
Debian
Redhat
Opensuse
Suse
Cross-site Scripting vulnerability in multiple products

The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.

6.1

0 Low Vulnerabilities

DATE CVE VENDOR VULNERABILITY CVSS