Mozilla Multiple Vulnerabilities...

- AV AC AU C I A
发布: 2002-09-18
修订: 2025-04-13

A number of vulnerabilities have been addressed in the Mozilla web browser between versions 1.00 and 1.0.1. The issues that have been addressed include: A problem in the browser causes navigator.plugins to leak path names. This may cause sensitive information to be leaked. Scripts may be executed by abusing the "file://" URI handler from XUL elements using HTTP redirects. Automatic loading of XML XLinks have been disabled in Mail. Automatic execution of XLinks in e-mail may assist in attacks. Styles could be used to read files cross-host. The consequence may be unauthorized access to sensitive files. A problem in Mail may allow a malicious e-mail to cause a denial of service. This is likely the issue described in Bugtraq ID 5002 "Netscape / Mozilla Malformed Email POP3 Denial Of Service Vulnerability". An issue in the browser may cause third-party cookies to be stolen through a proxy. This may allow unauthorized access to web services. The browser XMLSerializer does not include a...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息