Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00000.html
http://lists.opensuse.org/opensuse-security-announce/2015-10/msg00005.html
http://www.mozilla.org/security/announce/2015/mfsa2015-104.html
http://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.html
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
http://www.securityfocus.com/bid/76815
http://www.securitytracker.com/id/1033640
http://www.ubuntu.com/usn/USN-2743-1
http://www.ubuntu.com/usn/USN-2743-2
http://www.ubuntu.com/usn/USN-2743-3
OR
cpe:2.3:a:mozilla:firefox:*:*:*:*:*:*:*:* versions up to 40.0.3 (inclusive)
ID | Name | Product | Family | Severity |
---|---|---|---|---|
86291 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : firefox regression (USN-2743-4) | Nessus | Ubuntu Local Security Checks | high |
86282 | openSUSE Security Update : seamonkey (openSUSE-2015-632) | Nessus | SuSE Local Security Checks | high |
86238 | openSUSE Security Update : MozillaFirefox (openSUSE-2015-619) | Nessus | SuSE Local Security Checks | high |
8948 | Mozilla Firefox < 41.0 Multiple Vulnerabilities | Nessus Network Monitor | Web Clients | high |
86144 | Ubuntu 14.04 LTS / 15.04 : unity-firefox-extension, webapps-greasemonkey, webaccounts-browser-extension update (USN-2743-3) | Nessus | Ubuntu Local Security Checks | high |
86103 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : ubufox update (USN-2743-2) | Nessus | Ubuntu Local Security Checks | high |
86102 | Ubuntu 12.04 LTS / 14.04 LTS / 15.04 : firefox vulnerabilities (USN-2743-1) | Nessus | Ubuntu Local Security Checks | high |
86100 | Scientific Linux Security Update : firefox on SL5.x, SL6.x, SL7.x i386/x86_64 (20150922) | Nessus | Scientific Linux Local Security Checks | high |
86079 | FreeBSD : mozilla -- multiple vulnerabilities (2d56c7f4-b354-428f-8f48-38150c607a05) | Nessus | FreeBSD Local Security Checks | high |
86071 | Firefox < 41 Multiple Vulnerabilities | Nessus | Windows | high |
86069 | Firefox < 41 Multiple Vulnerabilities (Mac OS X) | Nessus | MacOS X Local Security Checks | high |