CVE-2017-7773
- EPSS 0.62%
- Veröffentlicht 15.04.2019 12:31:08
- Zuletzt bearbeitet 21.11.2024 03:32:37
Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.
CVE-2017-7774
- EPSS 0.56%
- Veröffentlicht 15.04.2019 12:31:08
- Zuletzt bearbeitet 21.11.2024 03:32:38
Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.
CVE-2017-7776
- EPSS 0.62%
- Veröffentlicht 15.04.2019 12:31:08
- Zuletzt bearbeitet 21.11.2024 03:32:38
Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.
CVE-2017-7777
- EPSS 0.5%
- Veröffentlicht 15.04.2019 12:31:08
- Zuletzt bearbeitet 21.11.2024 03:32:38
Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.
CVE-2017-7772
- EPSS 0.62%
- Veröffentlicht 12.04.2019 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:37
Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.
CVE-2018-12399
- EPSS 0.41%
- Veröffentlicht 28.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:08
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not ...
CVE-2018-12400
- EPSS 0.3%
- Veröffentlicht 28.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:08
In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox ...
CVE-2018-12401
- EPSS 0.88%
- Veröffentlicht 28.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:08
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.
CVE-2018-12402
- EPSS 0.36%
- Veröffentlicht 28.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:08
The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windo...
CVE-2018-12403
- EPSS 0.5%
- Veröffentlicht 28.02.2019 18:29:01
- Zuletzt bearbeitet 21.11.2024 03:45:09
If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.