CVE-2017-5395
- EPSS 0.38%
- Veröffentlicht 11.06.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:27:31
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for And...
CVE-2017-5396
- EPSS 1.7%
- Veröffentlicht 11.06.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:27:31
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
- EPSS 0.55%
- Veröffentlicht 11.06.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:27:31
The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to...
- EPSS 3.43%
- Veröffentlicht 11.06.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:27:31
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52,...
- EPSS 0.77%
- Veröffentlicht 11.06.2018 21:29:03
- Zuletzt bearbeitet 21.11.2024 03:27:31
Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52 and Th...
CVE-2016-9896
- EPSS 1.62%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:01:57
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
CVE-2016-9897
- EPSS 3.95%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:01:58
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9898
- EPSS 2.74%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:01:58
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9899
- EPSS 39.49%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:01:58
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9900
- EPSS 1.44%
- Veröffentlicht 11.06.2018 21:29:02
- Zuletzt bearbeitet 21.11.2024 03:01:58
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and T...