Zerosecurity
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Data Breaches
  • Crypto
  • Privacy
  • Downloads
    • Malwarebytes
    • Exploits
    • Paper Downloads
    • Software & Service Reviews
No Result
View All Result
SUBSCRIBE
Zerosecurity
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Data Breaches
  • Crypto
  • Privacy
  • Downloads
    • Malwarebytes
    • Exploits
    • Paper Downloads
    • Software & Service Reviews
No Result
View All Result
Zerosecurity
No Result
View All Result
Home Exploits

Firefox 15 Updates fix issues and 16 Vulnerabilities

Paul Anderson by Paul Anderson
September 7, 2012
in Exploits, Security
1
mozilla
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

mozilla firefoxMozilla has released an update to version 15 of Firefox to correct a bug in the web browser’s Private Browsing feature. Private Browsing is intended to allow users to browse the internet without saving any data about the sites and pages they’ve visited. However an error in the recent Firefox 15.0 release meant that Firefox was storing sites visited in its cache while Private Browsing was enabled.

You might also like

BreachForums Owner Arrested and Charged

Plex media server seen exploited in the wild utilizing a 3 year old RCE

New TPM 2.0 exploit attackers to access or overwrite sensitive data

According to the Bugzilla entry for the problem, upon turning off Private Browsing mode, this cached information could still be manually accessed or read by using a Firefox add-on such as CacheViewer Continued or other tools.

Firefox 15.0.1 is available to download for Windows, Mac OS X and Linux from the project’s site. Existing users should receive an automated update notification; alternatively, users can manually check for the update.

Mozilla has detailed the security vulnerabilities that have been fixed in both products. The fixes include seven critical vulnerabilities in Firefox, five of which are also present in Thunderbird. All in all, the new version of Firefox addresses 16 vulnerabilities while the new Thunderbird version closes 12 holes.

The bug fixes close several memory-related critical vulnerabilities that could be exploited by remote attackers to execute arbitrary code on a target system. Both Firefox and Thunderbird were affected by a vulnerability that allowed an attacker to inject code into the web console and use eval() to run it in a privileged context. This could allow malicious sites to execute arbitrary code when the console is invoked by the user. This problem, rated as high on Mozilla’s scale, has now been fixed. Further security vulnerabilities, two of them rated critical, were closed in the Graphite 2 library, in WebGL and in the SVG rendering engine which are all used by both Firefox and Thunderbird.

Complete lists of all fixed vulnerabilities are available for Firefox and Thunderbird. This information is also available for SeaMonkey; version 2.12 of SeaMonkey fixes the same vulnerabilities as Thunderbird 15.

Mozilla has also released new versions of the Extended Support Releases (ESR) for both Firefox and Thunderbird. Firefox ESR 10.0.7 fixes ten vulnerabilities, five of which are critical, while Thunderbird ESR 10.0.7 closes the same five critical vulnerabilities, closing nine security holes in total.

A new security feature in Firefox 15 that is worth noting is the ability for the browser to automatically update itself in the background. Firefox will now install all updates behind the scenes and only prompts users to restart the browser afterwards to apply the updates.

Tags: firefoxfixmozillapatchupdate
Share30Tweet19
Paul Anderson

Paul Anderson

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the top of the page.

Recommended For You

BreachForums Owner Arrested and Charged

by Paul Anderson
March 17, 2023
0
BreachForums Owner Arrested and Charged

On Wednesday afternoon, federal agents arrested a man in Peekskill, New York, for allegedly running a dark web data breach site known as "BreachForums." The suspect, Conor Brian...

Read more

Plex media server seen exploited in the wild utilizing a 3 year old RCE

by Kyle
March 11, 2023
0
Plex RCE responsible-for lastpass breach

CISA, the cybersecurity and infrastructure agency, has included a severe remote code execution (RCE) vulnerability in the Plex Media Server, which is nearly three years old, in its...

Read more

New TPM 2.0 exploit attackers to access or overwrite sensitive data

by Paul Anderson
March 5, 2023
0
New TPM 2.0 Exploit

Two buffer overflow vulnerabilities have been discovered in the Trusted Platform Module (TPM) 2.0 specification, which could give cybercriminals unauthorized access to or the ability to overwrite sensitive...

Read more

Stolen credit card market BidenCash leaks over 2 million credit cards

by Paul Anderson
March 3, 2023
0
Stolen credit card market BidenCash leaks over 2 million credit cards

BidenCash, a marketplace that focuses on carding, has leaked a database of 2,165,700 credit and debit cards to celebrate its first anniversary. Instead of keeping the leak a...

Read more

Google reports a rise in ransomware attacks

by Paul Anderson
July 15, 2022
0
Google reports a rise in ransomware attacks

In the 3rd issue of the recently released, Threat Horizons, Google's Cybersecurity Action Team (GCAT) provides organizations with information about emerging risks and actionable mitigation. Bad actors have...

Read more
Next Post
Dakia & ITChowk Hacked

Dakia & ITChowk Hacked

Related News

Netwire RAT seized by FBI and other worldwide police agencies

Netwire RAT seized by FBI and other worldwide police agencies

March 16, 2023
The Emotet botnet returns and is sending a slew of malicious emails

The Emotet botnet returns and is sending a slew of malicious emails

March 14, 2023
Update-resistant malware infects SonicWall security appliances

Update-resistant malware infects SonicWall security appliances

March 12, 2023
Zerosecurity

We cover the latest in Information Security & Blockchain news, as well as threat trends targeting both sectors.

Categories

  • Crypto
  • Data Breaches
  • DotNet Framework
  • Downloads
  • Exploits
  • Exploits
  • Information
  • Legal
  • Malware
  • Malware Analysis
  • Mobile Security
  • Paper Downloads
  • Piracy
  • Privacy
  • Programming
  • Public
  • Security
  • Security
  • Software & Service Reviews
  • Technology News
  • Tools
  • Tutorials
  • Video Tutorials
  • Whitepapers
  • Zero Security
  • Contact Us
  • List of our Writers

© 2022 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Tools
  • Contact Us
  • Privacy Policy

© 2022 ZeroSecurity, All Rights Reserved.