siamvorti.blogg.se

Firefox esr 60
Firefox esr 60










firefox esr 60

WebRTC can use a WrappedI420Buffer pixel buffer but the owning image object can be freed while it is still in use. #CVE-2018-5160: Uninitialized memory use by WebRTC encoder This could lead to a potentially exploitable crash triggerable by web content. #CVE-2018-5159: Integer overflow and out-of-bounds write in SkiaĪn integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes.

#Firefox esr 60 pdf#

This JavaScript can then be run with the permissions of the PDF viewer by its worker. The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. #CVE-2018-5158: Malicious PDF can inject JavaScript into PDF Viewer This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. #CVE-2018-5157: Same-origin bypass of PDF Viewer to view protected PDF files This results in a potentially exploitable crash. #CVE-2018-5155: Use-after-free with SVG animations and text pathsĪ use-after-free vulnerability can occur while adjusting layout during SVG animations with text paths. #CVE-2018-5154: Use-after-free with SVG animations and clip pathsĪ use-after-free vulnerability can occur while enumerating attributes during SVG animations with clip paths.

firefox esr 60

Security vulnerabilities fixed in Firefox 60 Mozilla Foundation Security Advisory 2018-11












Firefox esr 60