CVE-2017-5412
- EPSS 0.38%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:34
A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5413
- EPSS 0.59%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:34
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5414
- EPSS 0.13%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:34
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects ...
CVE-2017-5415
- EPSS 29.15%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:34
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.
CVE-2017-5416
- EPSS 0.86%
- Published 11.06.2018 21:29:04
- Last modified 21.11.2024 03:27:34
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5380
- EPSS 2.03%
- Published 11.06.2018 21:29:03
- Last modified 21.11.2024 03:27:29
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5381
- EPSS 1.26%
- Published 11.06.2018 21:29:03
- Last modified 21.11.2024 03:27:29
The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerabilit...
CVE-2017-5382
- EPSS 1.01%
- Published 11.06.2018 21:29:03
- Last modified 21.11.2024 03:27:29
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal information not meant to be seen by web content. This vulnerability affects Firefox < 51.
CVE-2017-5383
- EPSS 2.44%
- Published 11.06.2018 21:29:03
- Last modified 21.11.2024 03:27:29
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and ...
CVE-2017-5384
- EPSS 0.81%
- Published 11.06.2018 21:29:03
- Last modified 21.11.2024 03:27:29
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information than would be sent to the proxy itself in the case of HTTPS. Normally the Proxy Auto-Config file is spec...