This script is Copyright (C) 2008-2017 Tenable Network Security, Inc.
The remote Windows host contains a web browser that is affected by
The installed version of Firefox is affected by various security
- Several stability bugs leading to crashes which, in
some cases, show traces of memory corruption
- A vulnerability involving violation of the same-origin
policy could allow for cross-site scripting attacks
JARs and executed under the context of the JAR's signer
- By taking advantage of the privilege level stored in
the pre-compiled 'fastload' file, an attacker may be
privileges (MFSA 2008-24).
- Arbitrary code execution is possible in
'mozIJSSubScriptLoader.loadSubScript()' (MFSA 2008-25).
- An attacker can steal files from known locations on a
victim's computer via originalTarget and DOM Range
- It is possible for a malicious Java applet to bypass
the same-origin policy and create arbitrary socket
connections to other domains (MFSA 2008-28).
- An improperly encoded '.properties' file in an add-on
can result in uninitialized memory being used, which
could lead to data formerly used by other programs
being exposed to the add-on code (MFSA 2008-29).
- File URLs in directory listings are not properly HTML-
escaped when the filenames contained particular
characters (MFSA 2008-30).
- A weakness in the trust model regarding alt names on
peer-trusted certs could lead to spoofing secure
connections to any other site (MFSA 2008-31).
- URL shortcut files on Windows (for example, saved IE
favorites) could be interpreted as if they were in the
local file context when opened by Firefox, although
the referenced remote content would be downloaded and
displayed (MFSA 2008-32).
- A crash in Mozilla's block reflow code could be used
by an attacker to crash the browser and run arbitrary
code on the victim's computer (MFSA 2008-33).
See also :
Upgrade to Firefox 188.8.131.52 or later.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : true
Nessus Plugin ID: 33393 ()
Bugtraq ID: 30038
Get Nessus Professional to scan unlimited IPs, run compliance checks & moreBuy Nessus Professional Now