CVE-2016-9902
- EPSS 0.41%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 25.11.2025 17:50:16
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. ...
CVE-2017-5376
- EPSS 1.89%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 25.11.2025 17:50:16
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5378
- EPSS 1.8%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 25.11.2025 17:50:16
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerab...
CVE-2016-9079
- EPSS 84.81%
- Veröffentlicht 11.06.2018 21:29:01
- Zuletzt bearbeitet 04.11.2025 14:34:27
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR <...
CVE-2016-9893
- EPSS 2.82%
- Veröffentlicht 11.06.2018 21:29:01
- Zuletzt bearbeitet 25.11.2025 17:50:16
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50....
CVE-2016-9895
- EPSS 0.71%
- Veröffentlicht 11.06.2018 21:29:01
- Zuletzt bearbeitet 25.11.2025 17:50:16
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2018-12020
- EPSS 1.64%
- Veröffentlicht 08.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:25
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" optio...
CVE-2018-11235
- EPSS 39.68%
- Veröffentlicht 30.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:57
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that ...
CVE-2018-1000199
- EPSS 0.48%
- Veröffentlicht 24.05.2018 13:29:01
- Zuletzt bearbeitet 21.11.2024 03:39:55
The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptra...
CVE-2018-1087
- EPSS 0.04%
- Veröffentlicht 15.05.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:09
kernel KVM before versions kernel 4.16, kernel 4.16-rc7, kernel 4.17-rc1, kernel 4.17-rc2 and kernel 4.17-rc3 is vulnerable to a flaw in the way the Linux kernel's KVM hypervisor handled exceptions delivered after a stack switch operation via Mov SS ...