Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
modules/libpr0n/decoders/bmp/nsBMPDecoder.cpp in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 does not properly perform certain calculations related to the mColors table, which allows remote attackers to read portions of memory uninitialized via a crafted 8-bit bitmap (BMP) file that triggers an out-of-bounds read within the heap, as demonstrated using a CANVAS element; or cause a denial of service (application crash) via a crafted 8-bit bitmap file that triggers an out-of-bounds read. NOTE: the initial public reports stated that this affected Firefox in Ubuntu 6.06 through 7.10.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
FireFox/Opera浏览器 BMP图形处理 信息泄露漏洞
Vulnerability Description
FireFox和Opera都是流行的WEB浏览器。 Opera和FireFox负责解析带有部分模板的BMP文件的代码存在漏洞,特制的BMP文件可能会泄露堆上的信息,然后使用canvas标签(HTML 5)和Javascript将这些信息发送给远程服务器。 BMP格式中的BITMAPINFOHEADER中包含有一个名为biClrUsed的字段,用于说明模板中使用了多少颜色。如果该字段为0,则使用256色模板;如果非0,模板中就包含有指定数目的颜色。Opera和FireFox使用biClrUsed * siz
CVSS Information
N/A
Vulnerability Type
N/A