New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 6.7
SynopsisThe remote openSUSE host is missing a security update.
DescriptionThis is a MozillaThunderbird update to version 24.5.0 :
- MFSA 2014-34/CVE-2014-1518 Miscellaneous memory safety hazards
- MFSA 2014-37/CVE-2014-1523 (bmo#969226) Out of bounds read while decoding JPG images
- MFSA 2014-38/CVE-2014-1524 (bmo#989183) Buffer overflow when using non-XBL object as XBL
- MFSA 2014-42/CVE-2014-1529 (bmo#987003) Privilege escalation through Web Notification API
- MFSA 2014-43/CVE-2014-1530 (bmo#895557) Cross-site scripting (XSS) using history navigations
- MFSA 2014-44/CVE-2014-1531 (bmo#987140) Use-after-free in imgLoader while resizing images
- MFSA 2014-46/CVE-2014-1532 (bmo#966006) Use-after-free in nsHostResolver
- use shipped-locales as the authoritative source for supported locales (some unsupported locales disappear from -other package)
SolutionUpdate the affected MozillaThunderbird packages.