Firefox 3.5.x < 3.5.4 Multiple Vulnerabilities

High Nessus Plugin ID 42306


The remote Windows host contains a web browser that is affected by multiple vulnerabilities.


The installed version of Firefox 3.5 is earlier than 3.5.4. Such versions are potentially affected by the following security issues :

- It may be possible for a malicious web page to steal form history. (MFSA 2009-52)

- By predicting the filename of an already downloaded file in the downloads directory, a local attacker may be able to trick the browser into opening an incorrect file. (MFSA 2009-53)

- Recursive creation of JavaScript web-workers could crash the browser or allow execution of arbitrary code on the remote system.
(MFSA 2009-54)

- Provided the browser is configured to use Proxy Auto-configuration it may be possible for an attacker to crash the browser or execute arbitrary code. (MFSA 2009-55)

- Mozilla's GIF image parser is affected by a heap-based buffer overflow. (MFSA 2009-56)

- A vulnerability in XPCOM utility 'XPCVariant::VariantDataToJS' could allow executing arbitrary JavaScript code with chrome privileges. (MFSA 2009-57)

- A vulnerability in Mozilla's string to floating point number conversion routine could allow arbitrary code execution on the remote system. (MFSA 2009-59)

- It may be possible to read text from a web page using JavaScript function 'document.getSelection() from a different domain. (MFSA 2009-61)

- If a file contains right-to-left override character (RTL) in the filename it may be possible for an attacker to obfuscate the filename and extension of the file being downloaded. (MFSA 2009-62)

- Multiple memory safety bugs in media libraries could potentially allow arbitrary code execution.
(MFSA 2009-63)

- Multiple memory corruption vulnerabilities could potentially allow arbitrary code execution.
(MFSA 2009-64)


Upgrade to Firefox 3.5.4 or later.

See Also

Plugin Details

Severity: High

ID: 42306

File Name: mozilla_firefox_354.nasl

Version: $Revision: 1.22 $

Type: local

Agent: windows

Family: Windows

Published: 2009/10/29

Modified: 2017/06/09

Dependencies: 20862

Risk Information

Risk Factor: High


Base Score: 9.3

Temporal Score: 9.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:ND/RL:ND/RC:C

Vulnerability Information

CPE: cpe:/a:mozilla:firefox

Required KB Items: Mozilla/Firefox/Version

Exploit Available: false

Exploit Ease: No known exploits are available

Patch Publication Date: 2009/10/27

Vulnerability Publication Date: 2009/10/27

Reference Information

CVE: CVE-2009-0689, CVE-2009-3370, CVE-2009-3371, CVE-2009-3372, CVE-2009-3373, CVE-2009-3374, CVE-2009-3375, CVE-2009-3376, CVE-2009-3377, CVE-2009-3378, CVE-2009-3379, CVE-2009-3380, CVE-2009-3381, CVE-2009-3382, CVE-2009-3383

BID: 36851, 36853, 36854, 36855, 36856, 36857, 36858, 36866, 36867, 36869, 36870, 36871, 36872, 36873, 36875

OSVDB: 55603, 59381, 59382, 59383, 59384, 59385, 59386, 59388, 59389, 59390, 59391, 59392, 59393, 59394, 59395, 61091

Secunia: 36649, 36711

CWE: 16, 119, 264, 399