CVE-2017-7782
- EPSS 0.51%
- Published 11.06.2018 21:29:08
- Last modified 21.11.2024 03:32:38
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. Thi...
CVE-2017-5460
- EPSS 2.02%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:40
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fi...
CVE-2017-5462
- EPSS 1.07%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:40
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been ...
CVE-2017-5463
- EPSS 0.77%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:40
Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of the addressbar as displayed to users. Note: This attack only affects Firefox for Android. Other opera...
CVE-2017-5464
- EPSS 2.02%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:40
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firef...
CVE-2017-5465
- EPSS 23.65%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:40
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird...
CVE-2017-5466
- EPSS 0.62%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:40
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (...
CVE-2017-5467
- EPSS 1.3%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:41
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5468
- EPSS 2.32%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:41
An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.
CVE-2017-5469
- EPSS 5.64%
- Published 11.06.2018 21:29:07
- Last modified 21.11.2024 03:27:41
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.