The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.
CVSS Details
- CVSS 3.1 Base Score: 8.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Gentoo Linux | — | Upgrade mail-client/mozilla-thunderbird-bin.Upgrade dev-libs/nss.Upgrade mail-client/thunderbird-bin.Upgrade net-libs/xulrunner-bin.Upgrade www-client/mozilla-firefox.Upgrade www-client/mozilla-firefox-bin.Upgrade net-libs/xulrunner.Upgrade www-client/firefox-bin.Upgrade www-client/firefox.Upgrade www-client/seamonkey.Upgrade www-client/icecat.Upgrade mail-client/mozilla-thunderbird.Upgrade www-client/seamonkey-bin.Upgrade mail-client/thunderbird. | Oct 30, 2017 | Mar 25, 2010 |
| Mfsa2010 11 | — | Upgrade to Mozilla Firefox version 3.0.18Upgrade to Mozilla Firefox version 3.5.8Upgrade to Mozilla Firefox version 3.6.2 | Jun 14, 2012 | Mar 25, 2010 |
| Mozilla Seamonkey | — | Upgrade to Mozilla SeaMonkey version 2.0.3 | Feb 3, 2012 | Mar 25, 2010 |
| Mozilla Thunderbird | — | Upgrade to Mozilla Thunderbird version 3.0.2 | Feb 22, 2012 | Mar 25, 2010 |
| Suse | — | Upgrade MozillaFirefox-translationsUpgrade mozilla-xulrunner192-translations-32bitUpgrade mozilla-xulrunner192-gnome-32bitUpgrade mozilla-xulrunner192-x86Upgrade mozilla-xulrunner192Upgrade MozillaFirefox-translations-otherUpgrade MozillaFirefoxUpgrade mozilla-xulrunner192-develUpgrade MozillaFirefox-develUpgrade mozilla-xulrunner192-32bitUpgrade mozilla-xulrunner192-translationsUpgrade mozilla-xulrunner192-gnomeUpgrade MozillaFirefox-translations-common | Aug 9, 2024 | Jun 28, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub