CVE-2017-5438
- EPSS 2.02%
- Published 11.06.2018 21:29:05
- Last modified 21.11.2024 03:27:37
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox...
CVE-2017-5439
- EPSS 2.02%
- Published 11.06.2018 21:29:05
- Last modified 21.11.2024 03:27:37
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 5...
CVE-2017-5440
- EPSS 2.02%
- Published 11.06.2018 21:29:05
- Last modified 21.11.2024 03:27:37
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. T...
CVE-2017-5400
- EPSS 0.57%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:31
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45....
CVE-2017-5401
- EPSS 2.31%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:32
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 4...
CVE-2017-5402
- EPSS 2.66%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:32
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR ...
CVE-2017-5404
- EPSS 23.67%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:32
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 4...
CVE-2017-5405
- EPSS 2.35%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:32
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
CVE-2017-5407
- EPSS 1.1%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:33
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violate...
CVE-2017-5408
- EPSS 1.07%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:33
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < ...