🎥 Video | YoutubePC-WELT: Diese KI sieht, was wir zocken! HMX 6(17.09.2026 um 15:45 Uhr)
🔧 ProgrammierungJulian Goldie SEO: NEW Flet 1.0 Just Dropped! 🤯(17.09.2026 um 16:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: AI Is Outrunning Your Patch Program(17.09.2026 um 16:00 Uhr)
🍏 iOS / Mac OSNach dem CEO-Wechsel: Cook trifft Trump und Xi(17.09.2026 um 14:57 Uhr)
🍏 iOS / Mac OSApple Music testing out countdown clocks for upcoming albums(17.09.2026 um 15:38 Uhr)
🎥 Video | YoutubePC-WELT: Diese KI sieht, was wir zocken! HMX 6(17.09.2026 um 15:45 Uhr)
🔧 ProgrammierungJulian Goldie SEO: NEW Flet 1.0 Just Dropped! 🤯(17.09.2026 um 16:00 Uhr)
🕵️ SicherheitslückenSecurity Weekly - A CRA Resource: AI Is Outrunning Your Patch Program(17.09.2026 um 16:00 Uhr)
🍏 iOS / Mac OSNach dem CEO-Wechsel: Cook trifft Trump und Xi(17.09.2026 um 14:57 Uhr)
🍏 iOS / Mac OSApple Music testing out countdown clocks for upcoming albums(17.09.2026 um 15:38 Uhr)
🐧 Unix Server 🕛 vor 2026 Jahren 5 Min Lesezeit CVE-2015-7201
0

USN-2833-1: Firefox vulnerabilities

Cyber Threat & Vulnerability Dossier
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
⛔ Dienstausfall (DoS) / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-119: Memory Corruption
Handlungsempfehlung: Kernel-Paket aktualisieren (apt upgrade linux-image / yum update kernel) und System neu starten.
Im CVE-Radar öffnen
↗ Quelle (ubuntu.com)
🗣️ Stimme:
📑 Inhaltsübersicht

Ubuntu Security Notice USN-2833-1


15th December, 2015


firefox vulnerabilities


A security issue affects these releases of Ubuntu and its
derivatives:


  • Ubuntu 15.10


  • Ubuntu 15.04


  • Ubuntu 14.04 LTS


  • Ubuntu 12.04 LTS


Summary


Firefox could be made to crash or run programs as your login if it
opened a malicious website.





Software description


  • firefox
    - Mozilla Open Source web browser










Details


Andrei Vaida, Jesse Ruderman, Bob Clary, Christian Holler, Jesse Ruderman,
Eric Rahm, Robert Kaiser, Harald Kirschner, and Michael Henretty
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. ()



Ronald Crane discovered three buffer overflows through code inspection.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (, )



Ronald Crane discovered a buffer overflow through code inspection. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. ()



It was discovered that Firefox allows for control characters to be set in
cookies. An attacker could potentially exploit this to conduct cookie
injection attacks on some web servers. ()



Abdulrahman Alqabandi discovered that hash symbol is incorrectly handled
when parsing data: URLs. An attacker could potentially exploit this to
conduct URL spoofing attacks. ()



Ronald Crane dicovered an integer overflow when processing MP4 format
video in some circumstances. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Firefox. ()



Masato Kinugawa discovered a cross-origin information leak in error events
in web workers. An attacker could potentially exploit this to obtain
sensitive information. (, ,
)



Kris Maglione discovered a mechanism where web content could use
WebExtension APIs to execute code with the privileges of a particular
WebExtension. If a user were tricked in to opening a specially crafted
website with a vulnerable extension installed, an attacker could
potentially exploit this to obtain sensitive information or conduct
cross-site scripting (XSS) attacks. (







.


After a standard system update you need to restart Firefox to make
all the necessary changes.





References




,

,

,

,

,

,

,

,

,

,

CVE-2015-7223


Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf ubuntu.com lesen.
↗ Original-Artikel auf ubuntu.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
1 Quelle
Mehr Angriffe, mehr Regulatorik, weniger Personal
1 Quelle
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
Tipp: Mit Pfeiltasten [ ← ] und [ → ] blättern
Ähnliche Beiträge
🔍 Verwandte News

Ähnliche Beiträge zu USN-2833-1: Firefox vulnerabilities

Thematisch verwandte Begriffe: USN28331, Firefox, vulnerabilities · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...