Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information from process memory by reading packet data, as demonstrated by availability of this API in a Firefox OS application.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Mozilla Firefox TCP Socket API实现信息泄露漏洞
Vulnerability Description
Mozilla Firefox是美国Mozilla基金会开发的一款开源Web浏览器。 Mozilla Firefox 40.0.3及之前版本的TCP Socket API实现过程中存在安全漏洞,该漏洞源于程序没有正确处理数组边界。远程攻击者可通过读取数据包数据利用该漏洞获取进程内存中的敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A