Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox/Thunderbird/SeaMonkey字体实现输入验证漏洞
Vulnerability Description
Mozilla Firefox/Thunderbird/SeaMonkey都是Mozilla发布的WEB浏览器。 Mozilla Firefox 3.5.16之前版本及3.6.13之前的3.6.x版本,Thunderbird 3.0.11之前版本及3.1.7之前的3.1.x版本,以及SeaMonkey之前的2.0.11版本在操作系统的字体实现使用前没有正确验证可下载字体。远程攻击者可以借助和@font-face层叠样式表(CSS)规则有关的向量执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A