<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Donna's SecurityFlash : Web Browser Issues</title><link>http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx</link><description>Tags: Web Browser Issues</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Fake IRS page and email, See which browser will protect user from phished site</title><link>http://msmvps.com/blogs/donna/archive/2007/10/26/fake-irs-page-and-email-see-which-browser-will-protect-user-from-phished-site.aspx</link><pubDate>Fri, 26 Oct 2007 14:18:18 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1265339</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=1265339</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=1265339</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/10/26/fake-irs-page-and-email-see-which-browser-will-protect-user-from-phished-site.aspx#comments</comments><description>See http://www.dozleng.com/updates/index.php?showtopic=16115 for screenshots. Result: Opera: 2 Firefox: 1 and 1 Internet Explorer: 2...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/10/26/fake-irs-page-and-email-see-which-browser-will-protect-user-from-phished-site.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1265339" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/General+Security+News/default.aspx">General Security News</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Donna_2700_s+Nook/default.aspx">Donna's Nook</category></item><item><title>Opera JPEG Processing Heap Corruption Vulnerabilities</title><link>http://msmvps.com/blogs/donna/archive/2007/01/09/opera-jpeg-processing-heap-corruption-vulnerabilities.aspx</link><pubDate>Tue, 09 Jan 2007 08:44:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:479116</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=479116</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=479116</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/09/opera-jpeg-processing-heap-corruption-vulnerabilities.aspx#comments</comments><description>Opera is vulnerable in parsing the JPEG file format. Discovered were four vulnerabilities, each in different segments of the file format. posidron will describe in this advisory the two important ones. 1 - ntdll.RtlAllocateHeap() DHT vulnerability 2 ...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/09/opera-jpeg-processing-heap-corruption-vulnerabilities.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=479116" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Opera Browser patched in secret</title><link>http://msmvps.com/blogs/donna/archive/2007/01/06/opera-browser-patched-in-secret.aspx</link><pubDate>Sat, 06 Jan 2007 23:13:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:474647</guid><dc:creator>donna</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=474647</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=474647</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/06/opera-browser-patched-in-secret.aspx#comments</comments><description>Opera patched two remote code execution holes secretly as per Heise Security. Changelog for v9.10 did not mention the said security patch. Details at http://www.heise-security.co.uk/news/83279...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/06/opera-browser-patched-in-secret.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=474647" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/General+Security+News/default.aspx">General Security News</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Internet Explorer MSXML3 Race Condition Memory Corruption Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2007/01/06/internet-explorer-msxml3-race-condition-memory-corruption-vulnerability.aspx</link><pubDate>Sat, 06 Jan 2007 00:37:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:472617</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=472617</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=472617</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2007/01/06/internet-explorer-msxml3-race-condition-memory-corruption-vulnerability.aspx#comments</comments><description>Microsoft Internet Explorer is prone to a remote memory-corruption vulnerability because of a race condition that may cause a NULL-pointer dereference, read or write operations to invalid addresses, or other memory-corruption issues. Attackers may likely...(&lt;a href="http://msmvps.com/blogs/donna/archive/2007/01/06/internet-explorer-msxml3-race-condition-memory-corruption-vulnerability.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=472617" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Mozilla Foundation Security Advisories (Dec. 19, 2006)</title><link>http://msmvps.com/blogs/donna/archive/2006/12/20/mozilla-foundation-security-advisories-dec-19-2006.aspx</link><pubDate>Wed, 20 Dec 2006 03:40:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:435211</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=435211</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=435211</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/20/mozilla-foundation-security-advisories-dec-19-2006.aspx#comments</comments><description>MFSA 2006-76 XSS using outer window's Function object MFSA 2006-75 RSS Feed-preview referrer leak MFSA 2006-74 Mail header processing heap overflows MFSA 2006-73 Mozilla SVG Processing Remote Code Execution MFSA 2006-72 XSS by setting img.src to BLOCKED...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/20/mozilla-foundation-security-advisories-dec-19-2006.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=435211" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Opera released v9.10 of Opera Browser by adding Phishing filter (fraud protection) and other fixes/improvements</title><link>http://msmvps.com/blogs/donna/archive/2006/12/18/opera-released-v9-10-of-opera-browser-by-adding-phishing-filter-fraud-protection-and-other-fixes-improvements.aspx</link><pubDate>Mon, 18 Dec 2006 15:59:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:431150</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=431150</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=431150</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/12/18/opera-released-v9-10-of-opera-browser-by-adding-phishing-filter-fraud-protection-and-other-fixes-improvements.aspx#comments</comments><description>If you are using Opera browser, get the latest version 9.10 which is available now. One of the new security enhancement is by adding a Fraud Protection (aka Phishing filter). See Opera's Fraud Protection in action by viewing the demo at http://portal...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/12/18/opera-released-v9-10-of-opera-browser-by-adding-phishing-filter-fraud-protection-and-other-fixes-improvements.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=431150" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/General+Security+News/default.aspx">General Security News</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Firefox 2.0 delayed by bug outbreak</title><link>http://msmvps.com/blogs/donna/archive/2006/08/19/108101.aspx</link><pubDate>Sat, 19 Aug 2006 04:10:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:108101</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=108101</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=108101</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/08/19/108101.aspx#comments</comments><description>The new version of open-source browser Firefox has been delayed for a month. Version 2.0, codenamed Bon Echo, had been due on 26 September but will now make its debut on 24 October. The test schedule has also been adjusted, with the second beta now appearing...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/08/19/108101.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=108101" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Mozilla Firefox XML Handler Race Condition Memory Corruption Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2006/08/19/108096.aspx</link><pubDate>Sat, 19 Aug 2006 03:31:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:108096</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=108096</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=108096</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/08/19/108096.aspx#comments</comments><description>Mozilla Firefox is prone to a remote memory-corruption vulnerability because of a race condition that may result in double-free or other memory-corruption issues. Attackers may likely exploit this issue to execute arbitrary machine code in the context...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/08/19/108096.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=108096" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>OneStat.com reported "Most Popular browsers by Country"</title><link>http://msmvps.com/blogs/donna/archive/2006/07/13/104643.aspx</link><pubDate>Thu, 13 Jul 2006 19:41:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:104643</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=104643</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=104643</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/07/13/104643.aspx#comments</comments><description>Global usage share Mozilla Firefox has increased according to OneStat.com OneStat.com reported that Mozilla Firefox's browsers have a total global usage share of 12.93 percent. The total usage share of Mozilla Firefox increased 1.14 percent since May...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/07/13/104643.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=104643" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>IE 7 can be reset finally </title><link>http://msmvps.com/blogs/donna/archive/2006/06/13/100979.aspx</link><pubDate>Tue, 13 Jun 2006 05:12:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:100979</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=100979</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=100979</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/06/13/100979.aspx#comments</comments><description>The IE team blogged today that Internet Explorer 7 in Windows XP and Vista can be reset if the browser become unstable due to badly written add-ons or side-effect of malware infection. They wrote... " We have heard from users on their need to recover...(&lt;a href="http://msmvps.com/blogs/donna/archive/2006/06/13/100979.aspx"&gt;read more&lt;/a&gt;)&lt;img src="http://msmvps.com/aggbug.aspx?PostID=100979" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Internet Explorer "mhtml:" Redirection Disclosure of Sensitive Information</title><link>http://msmvps.com/blogs/donna/archive/2006/04/27/92776.aspx</link><pubDate>Thu, 27 Apr 2006 15:36:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:92776</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=92776</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=92776</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/27/92776.aspx#comments</comments><description>&lt;P&gt;Internet Explorer "mhtml:" Redirection Disclosure of Sensitive Information&lt;/P&gt;
&lt;P&gt;Affected Software:&amp;nbsp; Microsoft Internet Explorer 6.x&lt;/P&gt;
&lt;P&gt;codedreamer has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to disclose potentially sensitive information.&lt;/P&gt;
&lt;P&gt;The vulnerability is caused due to an error in the handling of redirections for URLs with the "mhtml:" URI handler. This can be exploited to access documents served from another web site.&lt;/P&gt;
&lt;P&gt;Secunia has constructed a test, which is available at their &lt;A href="http://secunia.com/Internet_Explorer_Arbitrary_Content_Disclosure_Vulnerability_Test/"&gt;website&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. Other versions may also be affected.&lt;/P&gt;
&lt;P&gt;Solution:&amp;nbsp; Disable active scripting support.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://secunia.com/advisories/19738/"&gt;http://secunia.com/advisories/19738/&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=92776" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>IE7 For XP Beta 2: Has Firefox Met Its Match?</title><link>http://msmvps.com/blogs/donna/archive/2006/04/27/92696.aspx</link><pubDate>Thu, 27 Apr 2006 00:45:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:92696</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=92696</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=92696</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/27/92696.aspx#comments</comments><description>&lt;P&gt;The new public release of Internet Explorer Beta 2 is, according to Microsoft, more stable and ready to be used. But is it ready to go up against Firefox?&lt;/P&gt;
&lt;P&gt;Find out at &lt;A href="http://www.informationweek.com/showArticle.jhtml?articleID=186700892"&gt;http://www.informationweek.com/showArticle.jhtml?articleID=186700892&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Below is part of what Ed Bott blogged today:&lt;/P&gt;
&lt;P&gt;"&lt;EM&gt;If you're too busy, here’s the conclusion:&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;On a straight, feature-for-feature comparison, IE7 stacks up well against Firefox. If its improved security model lives up to its design specs, malware distributors will find it much more difficult to make a dishonest living, and the tabbed browsing features in the new release should make it much easier to deal with multiple pages.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The biggest hurdle that Internet Explorer has to overcome, however, is one that doesn’t fit on any features chart. Its tattered reputation - especially when it comes to security - has created an indelible negative impression among the technically savvy users who’ve enthusiastically adopted Firefox so far. Even if the final release of IE7 improves mightily over the current beta, building that new and improved reputation will be an uphill climb.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The security features in IE7 look good on paper, but this week's release marks the first time IE7 has been thrown into the crucible that is the Internet. The criminal gangs that control the malware racket are going to be gunning for IE7 and mercilessly probing for weaknesses. I'll need to see a year's worth of security bulletins before I’m ready to accept the idea that this time it really is different and IE7 is genuinely safe enough to recommend without reservation to friends and family members.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Good enough" isn’t good enough for Microsoft in the case of IE7. On issues of security in particular, they're going to have to earn back trust from a generation that's been burned pretty badly by security flaws in Windows and IE. That will take time, and there's no guarantee of success.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Meanwhile, Firefox has one pretty huge ally. Visit Google's home page using Internet Explorer today and you'll see the first ad to ever appear on that page - urging you to switch to Firefox&lt;/EM&gt;."&lt;/P&gt;
&lt;P&gt;&lt;U&gt;&lt;FONT color=#0000ff&gt;&lt;A href="http://www.edbott.com/weblog/?p=1313"&gt;http://www.edbott.com/weblog/?p=1313&lt;/A&gt;&lt;/FONT&gt;&lt;/U&gt;&lt;A href="http://feeds.feedburner.com/EdBott-WindowsandOfficeExpertise?m=872"&gt;&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=92696" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Mozilla Foundation Security Advisory 2006-27</title><link>http://msmvps.com/blogs/donna/archive/2006/04/27/92695.aspx</link><pubDate>Thu, 27 Apr 2006 00:35:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:92695</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=92695</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=92695</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/27/92695.aspx#comments</comments><description>&lt;P&gt;&lt;STRONG&gt;Title:&lt;/STRONG&gt;&amp;nbsp; Table Rebuilding Code Execution Vulnerability&lt;BR&gt;&lt;STRONG&gt;Impact:&lt;/STRONG&gt;&amp;nbsp; Critical&lt;BR&gt;&lt;STRONG&gt;Announced:&lt;/STRONG&gt;&amp;nbsp; April 21, 2006&lt;BR&gt;&lt;STRONG&gt;Reporter:&lt;/STRONG&gt;&amp;nbsp; TippingPoint and the Zero Day Initiative&lt;BR&gt;&lt;STRONG&gt;Products:&lt;/STRONG&gt;&amp;nbsp; Firefox, Thunderbird, Mozilla Suite&lt;BR&gt;&lt;STRONG&gt;Fixed in:&lt;/STRONG&gt;&amp;nbsp; &lt;BR&gt;Firefox 1.5.0.2&lt;BR&gt;Firefox 1.0.8&lt;BR&gt;Thunderbird 1.5.0.2&lt;BR&gt;Thunderbird 1.0.8&lt;BR&gt;SeaMonkey 1.0.1&lt;BR&gt;Mozilla Suite 1.7.13&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Description&lt;BR&gt;&lt;/STRONG&gt;An anonymous researcher for TippingPoint and the Zero Day Initiative reports that an invalid and nonsensical ordering of table-related tags causes Mozilla to use a negative array index. This invalid memory use can be exploited to run code of the attacker's choice.&lt;BR&gt;&amp;nbsp;&lt;BR&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&amp;nbsp; Upgrade to fixed version. &lt;/P&gt;
&lt;P&gt;Although JavaScript is not involved in the vulnerability itself, disabling JavaScript may prevent an attacker from effectively preparing memory in order to carry out the exploit.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.mozilla.org/security/announce/2006/mfsa2006-27.html"&gt;http://www.mozilla.org/security/announce/2006/mfsa2006-27.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Also in&lt;/EM&gt; &lt;A href="http://www.zone-h.org/advisories/read/id=8931"&gt;http://www.zone-h.org/advisories/read/id=8931&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vulnerability Details:&lt;/STRONG&gt;&lt;BR&gt;This vulnerability allows attackers to execute arbitrary code on vulnerable installations of the Mozilla/Firefox web browser and Thunderbird e-mail client. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious e-mail.&lt;/P&gt;
&lt;P&gt;The specific flaw exists within the routine RebuildConsideringRows() during the rebuilding of nonsensical table tags. When the Mozilla engine attempts to fix the malformed table, an attacker is capable of triggering a memory corruption that can lead to code execution from user-supplied data. &lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Vendor Response:&lt;BR&gt;&lt;/STRONG&gt;Mozilla has issued an update to correct this vulnerability. Further details are available at:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Disclosure Timeline:&lt;BR&gt;&lt;/STRONG&gt;2006.02.28 – Vulnerability reported to vendor &lt;BR&gt;2006.04.25 – Public release of advisory &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=92695" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category><category domain="http://msmvps.com/blogs/donna/archive/tags/Advisories/default.aspx">Advisories</category></item><item><title>Safari "rowspan" Attribute Denial of Service Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2006/04/25/92563.aspx</link><pubDate>Tue, 25 Apr 2006 18:51:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:92563</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=92563</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=92563</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/25/92563.aspx#comments</comments><description>&lt;P&gt;Affected Software:&lt;BR&gt;Safari 1.x&lt;BR&gt;Safari 2.x&lt;/P&gt;
&lt;P&gt;Yannick von Arx has discovered a vulnerability in Safari, which can be exploited by malicious people to cause a DoS (Denial of Service).&lt;/P&gt;
&lt;P&gt;The vulnerability is caused due to an error in the processing of "td" HTML tags with overly large values for the "rowspan" attribute. This can be exploited to consume a large amount of CPU and memory resources on a vulnerable system by tricking a user into visiting a malicious web site.&lt;/P&gt;
&lt;P&gt;Successful exploitation causes a vulnerable system to become unresponsive.&lt;/P&gt;
&lt;P&gt;The vulnerability has been confirmed in version 2.0.3 (417.9.2) and has also been reported in version 1.3.1 (312.3.1). Other versions may also be affected.&lt;/P&gt;
&lt;P&gt;Solution:&amp;nbsp; Do not visit untrusted web sites while working with unsaved sensitive information.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://secunia.com/advisories/19763/"&gt;http://secunia.com/advisories/19763/&lt;/A&gt;&lt;BR&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=92563" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Internet Explorer "object" Tag Memory Corruption Code Execution</title><link>http://msmvps.com/blogs/donna/archive/2006/04/25/92562.aspx</link><pubDate>Tue, 25 Apr 2006 18:49:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:92562</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=92562</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=92562</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/25/92562.aspx#comments</comments><description>&lt;P&gt;Affected Software:&amp;nbsp; Microsoft Internet Explorer 6.x&lt;/P&gt;
&lt;P&gt;Michal Zalewski has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system.&lt;/P&gt;
&lt;P&gt;The vulnerability is caused due to an error in the processing of certain sequences of nested "object" HTML tags. This can be exploited to corrupt memory by tricking a user into visiting a malicious web site.&lt;/P&gt;
&lt;P&gt;Successful exploitation allows execution of arbitrary code.&lt;/P&gt;
&lt;P&gt;The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP2. Other versions may also be affected.&lt;/P&gt;
&lt;P&gt;Solution: Do not visit untrusted web sites.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://secunia.com/advisories/19762/"&gt;http://secunia.com/advisories/19762/&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=92562" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Firefox "focus()" Memory Corruption Weakness</title><link>http://msmvps.com/blogs/donna/archive/2006/04/25/92561.aspx</link><pubDate>Tue, 25 Apr 2006 18:47:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:92561</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=92561</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=92561</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/25/92561.aspx#comments</comments><description>&lt;P&gt;Affected Software: Mozilla Firefox 1.x&lt;/P&gt;
&lt;P&gt;A weakness has been discovered in Firefox, which can be exploited by malicious people to cause a DoS (Denial of Service).&lt;/P&gt;
&lt;P&gt;The weakness is caused due to an error in the handling of unexpected "focus()" JavaScript calls. This can be exploited to corrupt the memory and cause a crash by calling the "focus()" method on a container with specially crafted content.&lt;/P&gt;
&lt;P&gt;The weakness has been confirmed in version 1.5.0.2. Other versions may also be affected.&lt;/P&gt;
&lt;P&gt;Solution: Disable JavaScript when visiting untrusted web sites.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://secunia.com/advisories/19802/"&gt;http://secunia.com/advisories/19802/&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=92561" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Netscape Memory Corruption Vulnerability</title><link>http://msmvps.com/blogs/donna/archive/2006/04/15/91116.aspx</link><pubDate>Sat, 15 Apr 2006 04:09:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:91116</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=91116</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=91116</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/15/91116.aspx#comments</comments><description>&lt;P&gt;Netscape Browser version 8.1 (User-agent: Windows; U; Windows NT 5.0; en-US; rv:1.7.5) Gecko/20060111 Netscape/8.1) is confirmed as affected to recently published memory corruption vulnerability described at &lt;A href="http://www.mozilla.org/security/announce/2006/mfsa2006-11.html"&gt;http://www.mozilla.org/security/announce/2006/mfsa2006-11.html&lt;/A&gt; .&lt;/P&gt;
&lt;P&gt;This could be exploited to run arbitrary code in the affected system.&lt;/P&gt;
&lt;P&gt;Solution status:&lt;BR&gt;No updated version available from the vendor at the time of reporting.&lt;/P&gt;
&lt;P&gt;Affected versions:&lt;BR&gt;Vulnerability has been confirmed in version 8.1 using Windows 2000 Professional SP4 fully patched. Other versions may also be affected.&lt;/P&gt;
&lt;P&gt;Workarounds:&lt;BR&gt;None working workarounds available.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://www.zone-h.org/advisories/read/id=8916"&gt;http://www.zone-h.org/advisories/read/id=8916&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=91116" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Firefox Browser: Security and Stability Update available</title><link>http://msmvps.com/blogs/donna/archive/2006/04/14/90878.aspx</link><pubDate>Thu, 13 Apr 2006 23:08:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:90878</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=90878</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=90878</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/14/90878.aspx#comments</comments><description>&lt;P&gt;Time to update your Firefox browser to v1.5.0.2.&amp;nbsp; It has security and stability fixes as per Mozilla.&lt;/P&gt;
&lt;P&gt;Via &lt;A href="http://www.dozleng.com/updates/index.php?&amp;amp;act=calendar&amp;amp;code=showevent&amp;amp;eventid=25149"&gt;Calendar of Updates&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=90878" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Internet Explorer Window Loading Race Condition Address Bar Spoofing</title><link>http://msmvps.com/blogs/donna/archive/2006/04/04/89251.aspx</link><pubDate>Tue, 04 Apr 2006 12:43:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:89251</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=89251</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=89251</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/04/04/89251.aspx#comments</comments><description>&lt;P&gt;Hai Nam Luke has discovered a vulnerability in Internet Explorer, which can be exploited by malicious people to conduct phishing attacks.&lt;/P&gt;
&lt;P&gt;The vulnerability is caused due to a race condition in the loading of web content and Macromedia Flash Format files (".swf") in browser windows. This can be exploited to spoof the address bar in a browser window showing a Flash file from a malicious web site.&lt;/P&gt;
&lt;P&gt;NOTE: The impact of exploitation is reduced because the URL of the malicious Flash file is visible in the title of the browser window.&lt;/P&gt;
&lt;P&gt;The vulnerability has been confirmed on a fully patched system with Internet Explorer 6.0 and Microsoft Windows XP SP1/SP2. Other versions may also be affected.&lt;/P&gt;
&lt;P&gt;Solution: Disable Active Scripting support.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://secunia.com/advisories/19521/"&gt;http://secunia.com/advisories/19521/&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=89251" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item><item><title>Internet Explorer Unspecified Automatic .HTA Application Execution</title><link>http://msmvps.com/blogs/donna/archive/2006/03/27/87983.aspx</link><pubDate>Mon, 27 Mar 2006 05:52:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:87983</guid><dc:creator>donna</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/rsscomments.aspx?PostID=87983</wfw:commentRss><wfw:comment xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/donna/commentapi.aspx?PostID=87983</wfw:comment><comments>http://msmvps.com/blogs/donna/archive/2006/03/27/87983.aspx#comments</comments><description>&lt;P&gt;Affected Software:&amp;nbsp;Microsoft Internet Explorer 6.x&lt;/P&gt;
&lt;P&gt;Jeffrey van der Stad has reported a vulnerability in Internet Explorer, which can be exploited by malicious people to compromise a user's system.&lt;/P&gt;
&lt;P&gt;The vulnerability is caused due to an unspecified error when handling .HTA applications and allows execution of the .HTA application on the user's system without any user interaction when e.g. visiting a malicious web site.&lt;/P&gt;
&lt;P&gt;The vulnerability has been reported in Internet Explorer 6.0. Other versions may also be affected.&lt;/P&gt;
&lt;P&gt;Solution:&amp;nbsp; Do not visit untrusted web sites.&lt;BR&gt;Disabling Active Scripting support may prevent exploitation, but has not been proven.&lt;/P&gt;
&lt;P&gt;&lt;A href="http://secunia.com/advisories/19378/"&gt;http://secunia.com/advisories/19378/&lt;/A&gt;&lt;/P&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=87983" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/donna/archive/tags/Web+Browser+Issues/default.aspx">Web Browser Issues</category></item></channel></rss>