New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 6.7
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThe Mozilla Firefox was updated to version 3.5.6, fixing lots of bugs and various security issues.
The following issues were fixed :
- MFSA 2009-65/CVE-2009-3979/CVE-2009-3980/CVE-2009-3982 Crashes with evidence of memory corruption (rv:188.8.131.52)
- MFSA 2009-66/CVE-2009-3388 (bmo#504843,bmo#523816) Memory safety fixes in liboggplay media library
- MFSA 2009-67/CVE-2009-3389 (bmo#515882,bmo#504613) Integer overflow, crash in libtheora video library
- MFSA 2009-68/CVE-2009-3983 (bmo#487872) NTLM reflection vulnerability
- MFSA 2009-69/CVE-2009-3984/CVE-2009-3985 (bmo#521461,bmo#514232) Location bar spoofing vulnerabilities
- MFSA 2009-70/CVE-2009-3986 (bmo#522430) Privilege escalation via chrome window.opener
SolutionUpdate the affected MozillaFirefox packages.