ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
SUBSCRIBE
ZeroSecurity - Information Security News
  • Home
  • Security
    • Exploits
    • Mobile Security
  • Malware
  • Breaches
  • Crypto
  • Privacy
  • Tech
    • AI
    • Downloads
      • Malwarebytes
      • Exploits
      • Paper Downloads
    • Reviews
No Result
View All Result
ZeroSecurity - Information Security News
No Result
View All Result
Home Exploits

Firefox 15 Updates fix issues and 16 Vulnerabilities

Paul by Paul
September 7, 2012
in Exploits, Security
Reading Time: 3 mins read
mozilla
Share on FacebookShare on Twitter

mozilla firefoxMozilla has released an update to version 15 of Firefox to correct a bug in the web browser’s Private Browsing feature. Private Browsing is intended to allow users to browse the internet without saving any data about the sites and pages they’ve visited. However an error in the recent Firefox 15.0 release meant that Firefox was storing sites visited in its cache while Private Browsing was enabled.

You might also like

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

How Hackers Still Manage to Compromise MFA

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

According to the Bugzilla entry for the problem, upon turning off Private Browsing mode, this cached information could still be manually accessed or read by using a Firefox add-on such as CacheViewer Continued or other tools.

Firefox 15.0.1 is available to download for Windows, Mac OS X and Linux from the project’s site. Existing users should receive an automated update notification; alternatively, users can manually check for the update.

Mozilla has detailed the security vulnerabilities that have been fixed in both products. The fixes include seven critical vulnerabilities in Firefox, five of which are also present in Thunderbird. All in all, the new version of Firefox addresses 16 vulnerabilities while the new Thunderbird version closes 12 holes.

The bug fixes close several memory-related critical vulnerabilities that could be exploited by remote attackers to execute arbitrary code on a target system. Both Firefox and Thunderbird were affected by a vulnerability that allowed an attacker to inject code into the web console and use eval() to run it in a privileged context. This could allow malicious sites to execute arbitrary code when the console is invoked by the user. This problem, rated as high on Mozilla’s scale, has now been fixed. Further security vulnerabilities, two of them rated critical, were closed in the Graphite 2 library, in WebGL and in the SVG rendering engine which are all used by both Firefox and Thunderbird.

Complete lists of all fixed vulnerabilities are available for Firefox and Thunderbird. This information is also available for SeaMonkey; version 2.12 of SeaMonkey fixes the same vulnerabilities as Thunderbird 15.

Mozilla has also released new versions of the Extended Support Releases (ESR) for both Firefox and Thunderbird. Firefox ESR 10.0.7 fixes ten vulnerabilities, five of which are critical, while Thunderbird ESR 10.0.7 closes the same five critical vulnerabilities, closing nine security holes in total.

A new security feature in Firefox 15 that is worth noting is the ability for the browser to automatically update itself in the background. Firefox will now install all updates behind the scenes and only prompts users to restart the browser afterwards to apply the updates.

Tags: firefoxfixmozillapatchupdate
Previous Post

AVG 2013 product line launched

Next Post

Dakia & ITChowk Hacked

Paul

Paul

Editor and chief at ZeroSecurity. Expertise includes programming, malware analysis, and penetration testing. If you would like to write for ZeroSecurity, please click "Contact us" at the bottom of the page.

Recommended For You

Photo of the CISCO logo and text saying "You have been hacked!"

Hackers Exploit Maximum-Severity Cisco Zero-Day Bug Since 2023 (CVE-2026-20127)

March 6, 2026
How Hackers Still Manage to Compromise MFA

How Hackers Still Manage to Compromise MFA

March 6, 2026

Anthropic Unveils Claude Code Security to Detect and Fix Critical Vulnerabilities

February 22, 2026

Phishing 2.0: How AI is Turning Cyber Attacks into a Science

January 7, 2025 - Updated on January 9, 2025

DoubleClickjacking – The Stealthy New Web Exploit Threatening User Security

January 1, 2025

Critical Vulnerabilities Exposed in Ruijie Networks Cloud Platform

December 25, 2024
Please login to join discussion

Related News

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

Malicious Chrome Extensions Steal AI Data and Hijack Revenue in DarkSpectre Campaign

January 30, 2026
KPMG Netherlands Listed as Victim by Nova Ransomware Group

KPMG Netherlands Listed as Victim by Nova Ransomware Group

January 24, 2026
RansomHouse Claims Breach of Key Apple Assembler Luxshare

RansomHouse Claims Breach of Key Apple Assembler Luxshare

January 20, 2026
ZeroSecurity - Information Security News

We cover the latest in technology news, Crypto, Artificial Intelligence, and the threat trends impacting these sectors.

Categories

Piracy

Tutorials

Programming

Malware Analysis

Downloads

  • Contact us
  • Press
  • Writers
  • Privacy Policy
  • Terms of Service

© 2026 ZeroSecurity, All Rights Reserved.

No Result
View All Result
  • Home
  • Security
    • Tools
  • Exploits
  • Data Breaches
  • Malware
  • Privacy
  • Mobile Security
  • Contact Us
    • Press
  • Privacy Policy

© 2026 ZeroSecurity, All Rights Reserved.

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.