Malware, Patch/Configuration Management, Phishing, Vulnerability Management

Mozilla releases Firefox 14 to close several major holes

Mozilla on Tuesday released Firefox version 14.0.1 to patch a slew of vulnerabilities. Five of the 18 bugs fixed are labeled as “critical,” giving attackers the ability to run malicious software. According to Mozilla's Security Advisories post, two of the most concerning flaws were discovered in the “javascript: URL,” which could allow miscreants to evade the JavaScript sandbox to execute malicious code, as well as “JSDependentString,” which may enable attackers to crash the browser and corrupt memory. The remaining vulnerabilities, if not patched, could facilitate the execution of arbitrary code, cross-site scripting and phishing attacks.

[An earlier version of this story incorrectly stated that 14 vulnerabilities were patched, when it was actually 18].

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms and Conditions and Privacy Policy.