Mozilla Suite, Firefox And Thunderbird Multiple Vulnerabilities

Some of the described vulnerabilities do not require exploits.

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

A proof-of-concept exmaple for MFSA 2005-55 is available at the following location:

https://bugzilla.mozilla.org/attachment.cgi?id=187392

A proof-of-concept example is available for MFSA 2005-46 at the following location:

https://bugzilla.mozilla.org/attachment.cgi?id=185575

Exploit code 'InstallVersion_exp' for the issue described in MFSA 2005-50 (CVE-2005-2265) has been released by Aviv Raff.

Metasploit Framework has released an exploit for MFSA 2005-50 (mozilla_compareto.pm).


 

Privacy Statement
Copyright 2010, SecurityFocus