网络实验室

 找回密码
 注册账户
查看: 699|回复: 0

Mozilla 1.7.6 Released

[复制链接]
admin 发表于 2012-3-22 20:10:29 | 显示全部楼层 |阅读模式
Mozilla is an open-source Web browser, designed for standards compliance, performance and portability.

Mozilla is a cousin to Netscape Communicator that is being developed by the Free Software Community with the cooperation and support of Netscape. What’s New in This Release:



· Drag and drop loading of privileged XUL

  · GIF heap overflow parsing Netscape extension 2

  · Internationalized Domain Name (IDN) homograph spoofing

  · Unsafe /tmp/plugtmp directory exploitable to erase user’s files

  · Plugins can be used to load privileged content

  · Cross-site scripting by dropping javascript: link on tab

  · Image drag and drop executable spoofing

  · HTTP auth prompt tab spoofing

  · Download dialog source spoofing

  · Overwrite arbitrary files downloading .lnk twice

  · XSLT can include stylesheets from arbitrary hosts

  · Memory overwrite in string library

  · Install source spoofing with user:pass@host

  · Spoofing download and security dialogs with overlapping windows

  · Heap overflow possible in UTF8 to Unicode conversion

  · SSL “secure site” indicator spoofing

  · Window Injection Spoofing

Download
您需要登录后才可以回帖 登录 | 注册账户

本版积分规则

黑屋|存档|手机|网络实验室 本站服务器由美国合租以及IDCLayer国际数据提供!!!

GMT+8, 2024-5-6 20:04 , Processed in 0.139210 second(s), 9 queries , Gzip On, Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2021, Tencent Cloud.

快速回复 返回顶部 返回列表