Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Pango pango_glyph_string_set_size()函数整数溢出漏洞
Vulnerability Description
Pango是一个开放源码的自由函数库,用于高质量地渲染国际化的文字。 Pango的pango_glyph_string_set_size函数在进行乘法运算时存在整数溢出漏洞: string glyphs = g_realloc (string glyphs, string space *sizeof (PangoGlyphInfo)); 如果用户受骗使用链接到该库的应用程序打开了包含有超长字型信息的恶意字体文件的话,就可能触发这个溢出,导致执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A