The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.
http://code.google.com/p/chromium/issues/detail?id=117627
http://googlechromereleases.blogspot.com/2012/04/stable-channel-update_30.html
http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00012.html
http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00031.html
http://lists.opensuse.org/opensuse-updates/2015-05/msg00036.html
http://rhn.redhat.com/errata/RHSA-2015-1012.html
http://secunia.com/advisories/48992
http://www.debian.org/security/2015/dsa-3260
http://www.mozilla.org/security/announce/2015/mfsa2015-57.html
http://www.securityfocus.com/bid/53309
http://www.securitytracker.com/id?1027001
https://bugzilla.mozilla.org/show_bug.cgi?id=1087565
https://exchange.xforce.ibmcloud.com/vulnerabilities/75271
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A14964
https://www.mozilla.org/en-US/security/known-vulnerabilities/thunderbird/#thunderbird31.7
OR
OR
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* versions up to 18.0.1025.166 (inclusive)
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 37.0.2 (inclusive)
cpe:2.3:a:mozilla:firefox_esr:*:*:*:*:*:*:*:* versions up to 31.6 (inclusive)
cpe:2.3:a:mozilla:seamonkey:*:*:*:*:*:*:*:* versions up to 2.33.0 (inclusive)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* versions up to 31.6 (inclusive)
cpe:2.3:a:mozilla:thunderbird:*:*:*:*:*:*:*:* versions up to 38.0 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
83801 | openSUSE Security Update : MozillaFirefox (openSUSE-2015-375) | Nessus | SuSE Local Security Checks | critical |
83800 | openSUSE Security Update : MozillaThunderbird (openSUSE-2015-374) | Nessus | SuSE Local Security Checks | critical |
83537 | RHEL 5 / 6 / 7 : thunderbird (RHSA-2015:1012) | Nessus | Red Hat Local Security Checks | critical |
83535 | Oracle Linux 6 / 7 : thunderbird (ELSA-2015-1012) | Nessus | Oracle Linux Local Security Checks | critical |
83530 | CentOS 5 / 6 / 7 : thunderbird (CESA-2015:1012) | Nessus | CentOS Local Security Checks | critical |
83464 | Mozilla Thunderbird < 31.7 Multiple Vulnerabilities | Nessus | Windows | critical |
83439 | Firefox < 38.0 Multiple Vulnerabilities | Nessus | Windows | critical |
83438 | Firefox ESR 31.x < 31.7 Multiple Vulnerabilities | Nessus | Windows | critical |
83423 | Debian DSA-3260-1 : iceweasel - security update | Nessus | Debian Local Security Checks | critical |
83389 | FreeBSD : mozilla -- multiple vulnerabilities (d9b43004-f5fd-4807-b1d7-dbf66455b244) | Nessus | FreeBSD Local Security Checks | critical |
74622 | openSUSE Security Update : chromium / v8 (openSUSE-SU-2012:0613-1) | Nessus | SuSE Local Security Checks | critical |
800935 | Google Chrome < 18.0.1025.168 Multiple Vulnerabilities | Log Correlation Engine | Web Clients | high |
6783 | Google Chrome < 18.0.1025.168 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
58963 | FreeBSD : chromium -- multiple vulnerabilities (94c0ac4f-9388-11e1-b242-00262d5ed8ee) | Nessus | FreeBSD Local Security Checks | critical |
58954 | Google Chrome < 18.0.1025.168 Multiple Vulnerabilities | Nessus | Windows | high |