Several remote vulnerabilities have been discovered in Xulrunner, a
runtime environment for XUL applications, such as the Iceweasel web
browser. The Common Vulnerabilities and Exposures project identifies
the following problems:
CVE-2009-1571
Alin Rad Pop discovered that incorrect memory handling in the
HTML parser could lead to the execution of arbitrary code.
CVE-2009-3988
Hidetake Jo discovered that the same-origin policy can be
bypassed through window.dialogArguments.
CVE-2010-0159
Henri Sivonen, Boris Zbarsky, Zack Weinberg, Bob Clary, Martijn
Wargers and Paul Nickerson reported crashes in layout engine,
which might allow the execution of arbitrary code.
CVE-2010-0160
Orlando Barrera II discovered that incorrect memory handling in the
implementation of the web worker API could lead to the execution
of arbitrary code.
CVE-2010-0162
Georgi Guninski discovered that the same origin policy can be
bypassed through specially crafted SVG documents.
For the ...
Get the latest Linux and open source security news straight to your inbox.