Nicolas Derouet discovered that Iceape performs insufficient
validation of cookies, which could lead to denial of service.
CVE-2007-1558
Gatan Leurent discovered a cryptographical weakness in APOP
authentication, which reduces the required efforts for an MITM attack
to intercept a password. The update enforces stricter validation, which
prevents this attack.
CVE-2007-2867
Boris Zbarsky, Eli Friedman, Georgi Guninski, Jesse Ruderman, Martijn
Wargers and Olli Pettay discovered crashes in the layout engine, which
might allow the execution of arbitrary code.
CVE-2007-2868
Brendan Eich, Igor Bukanov, Jesse Ruderman, moz_bug_r_a4 and Wladimir Palant
discovered crashes in the javascript engine, which might allow the execution of
arbitrary code.
CVE-2007-2870
"moz_bug_r_a4" discovered that adding an event listener through the
addEventListener() function allows cross-site scripting.
CVE-2007-2871
Chris Thomas discovere...
Get the latest Linux and open source security news straight to your inbox.