CVE-2016-9905
- EPSS 1.24%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:01:59
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
CVE-2017-5373
- EPSS 2.03%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:27:28
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affe...
CVE-2017-5375
- EPSS 61.73%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:27:28
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5376
- EPSS 2.03%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:27:28
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5378
- EPSS 1.8%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:27:29
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerab...
CVE-2016-9079
- EPSS 84.96%
- Veröffentlicht 11.06.2018 21:29:01
- Zuletzt bearbeitet 21.03.2025 19:24:52
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR <...
CVE-2016-9893
- EPSS 2.82%
- Veröffentlicht 11.06.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:01:57
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50....
CVE-2016-9895
- EPSS 0.71%
- Veröffentlicht 11.06.2018 21:29:01
- Zuletzt bearbeitet 21.11.2024 03:01:57
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2018-12020
- EPSS 1.56%
- Veröffentlicht 08.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:25
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" optio...
CVE-2018-11235
- EPSS 41.72%
- Veröffentlicht 30.05.2018 04:29:00
- Zuletzt bearbeitet 21.11.2024 03:42:57
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that ...