| The browser engine in Mozilla Firefox 3.x before 3.0.9, Thunderbird
before 2.0.0.22, and SeaMonkey before 1.1.16 allows remote attackers
to cause a denial of service (application crash) and possibly trigger
memory corruption via vectors related to (1)
nsAsyncInstantiateEvent::Run, (2) nsStyleContext::Destroy, (3)
nsComputedDOMStyle::GetWidth, (4) the
xslt_attributeset_ImportSameName.html test case for the XSLT
stylesheet compiler, (5) nsXULDocument::SynchronizeBroadcastListener,
(6) IsBindingAncestor, (7) PL_DHashTableOperate and
nsEditor::EndUpdateViewBatch, and (8)
gfxSkipCharsIterator::SetOffsets, and other vectors.
|