CVE-2016-10196
- EPSS 1.06%
- Veröffentlicht 15.03.2017 15:59:00
- Zuletzt bearbeitet 25.11.2025 17:50:16
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string ar...
CVE-2016-5283
- EPSS 0.28%
- Veröffentlicht 22.09.2016 22:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resiz...
CVE-2016-5284
- EPSS 0.55%
- Veröffentlicht 22.09.2016 22:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X....
CVE-2016-5282
- EPSS 0.39%
- Veröffentlicht 22.09.2016 22:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.
CVE-2016-5281
- EPSS 2.55%
- Veröffentlicht 22.09.2016 22:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code a...
CVE-2016-5280
- EPSS 2.5%
- Veröffentlicht 22.09.2016 22:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirec...
CVE-2016-5279
- EPSS 0.38%
- Veröffentlicht 22.09.2016 22:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
CVE-2016-5278
- EPSS 1.49%
- Veröffentlicht 22.09.2016 22:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled ...
CVE-2016-5277
- EPSS 2.26%
- Veröffentlicht 22.09.2016 22:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup...
CVE-2016-5276
- EPSS 1.92%
- Veröffentlicht 22.09.2016 22:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denia...