Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications, such as the Iceweasel web
browser. The Common Vulnerabilities and Exposures project identifies
the following problems:
CVE-2009-3070
Jesse Ruderman discovered crashes in the layout engine, which
might allow the execution of arbitrary code.
CVE-2009-3071
Daniel Holbert, Jesse Ruderman, Olli Pettay and "toshi" discovered
crashes in the layout engine, which might allow the execution of
arbitrary code.
CVE-2009-3072
Josh Soref, Jesse Ruderman and Martin Wargers discovered crashes
in the layout engine, which might allow the execution of arbitrary
code.
CVE-2009-3074
Jesse Ruderman discovered a crash in the Javascript engine, which
might allow the execution of arbitrary code.
CVE-2009-3075
Carsten Book and "Taral" discovered crashes in the layout engine,
which might allow the execution of arbitrary code.
CVE-2009-3076
Jesse Ruderman discovered that t...