[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS2-2019-1195 --- thunderbird

ID: oval:org.secpod.oval:def:1700163Date: (C)2019-06-25   (M)2023-12-20
Class: PATCHFamily: unix




When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. Type inference is incorrect for constructors entered through on-stack replacement with IonMonkey Improper bounds checks when Spectre mitigations are disabled Use-after-free when removing in-use DOM elements Ionmonkey type confusion with __proto__ mutations IonMonkey MArraySlice has incorrect alias information Type-confusion in IonMonkey JIT compiler Use-after-free with SMIL animation controller Memory safety bugs fixed in Mozilla libraries IonMonkey leaks JS_OPTIMIZED_OUT magic value to script

Platform:
Amazon Linux 2
Product:
thunderbird
Reference:
ALAS2-2019-1195
CVE-2019-9788
CVE-2018-18506
CVE-2019-9813
CVE-2019-9810
CVE-2019-9790
CVE-2019-9791
CVE-2019-9792
CVE-2019-9793
CVE-2019-9795
CVE-2019-9796
CVE    10
CVE-2018-18506
CVE-2019-9793
CVE-2019-9796
CVE-2019-9795
...
CPE    2
cpe:/a:mozilla:thunderbird
cpe:/o:amazon:linux:2

© SecPod Technologies