CVE-2017-7842
- EPSS 0.36%
- Veröffentlicht 11.06.2018 21:29:11
- Zuletzt bearbeitet 21.11.2024 03:32:46
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer...
CVE-2017-7843
- EPSS 1.12%
- Veröffentlicht 11.06.2018 21:29:11
- Zuletzt bearbeitet 21.11.2024 03:32:46
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple pr...
CVE-2017-7844
- EPSS 1.34%
- Veröffentlicht 11.06.2018 21:29:11
- Zuletzt bearbeitet 21.11.2024 03:32:47
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website to query user history. Note: Th...
CVE-2017-7805
- EPSS 3.85%
- Veröffentlicht 11.06.2018 21:29:10
- Zuletzt bearbeitet 21.11.2024 03:32:41
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocat...
CVE-2017-7806
- EPSS 1.72%
- Veröffentlicht 11.06.2018 21:29:10
- Zuletzt bearbeitet 21.11.2024 03:32:42
A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.
CVE-2017-7807
- EPSS 0.82%
- Veröffentlicht 11.06.2018 21:29:10
- Zuletzt bearbeitet 21.11.2024 03:32:42
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird...
CVE-2017-7808
- EPSS 0.13%
- Veröffentlicht 11.06.2018 21:29:10
- Zuletzt bearbeitet 21.11.2024 03:32:42
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability a...
CVE-2017-7809
- EPSS 2.41%
- Veröffentlicht 11.06.2018 21:29:10
- Zuletzt bearbeitet 21.11.2024 03:32:42
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox E...
- EPSS 2.51%
- Veröffentlicht 11.06.2018 21:29:10
- Zuletzt bearbeitet 21.11.2024 03:32:42
Memory safety bugs were reported in Firefox 55 and Firefox ESR 52.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affect...
- EPSS 2.22%
- Veröffentlicht 11.06.2018 21:29:10
- Zuletzt bearbeitet 21.11.2024 03:32:42
Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56.