Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox和Firefox ESR 内存损坏漏洞
Vulnerability Description
Mozilla Firefox和Firefox ESR都是美国Mozilla基金会开发的浏览器产品。Firefox是一款开源Web浏览器;Firefox ESR是Firefox的一个延长支持版本。 Mozilla Firefox 40.0之前版本和Firefox ESR 38.2之前38.x版本的‘mozilla::AudioSink’函数中存在安全漏洞,该漏洞源于程序没有正确处理MP3音频数据中不一致的样本格式。远程攻击者可借助畸形的文件利用该漏洞执行任意代码,或造成拒绝服务(越边界读取)。
CVSS Information
N/A
Vulnerability Type
N/A