CVE-2016-2793
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:32
- Zuletzt bearbeitet 12.04.2025 10:46:40
CachedCmap.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphi...
CVE-2016-2792
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:31
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graphite2::Slot::getAttr function in Slot.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecifie...
CVE-2016-2791
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:30
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graphite2::GlyphCache::glyph function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other ...
CVE-2016-2790
- EPSS 0.79%
- Veröffentlicht 13.03.2016 18:59:29
- Zuletzt bearbeitet 12.04.2025 10:46:40
The graphite2::TtfUtil::GetTableInfo function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a ...
CVE-2016-1979
- EPSS 0.91%
- Veröffentlicht 13.03.2016 18:59:28
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the PK11_ImportDERPrivateKeyInfoAndReturnKey function in Mozilla Network Security Services (NSS) before 3.21.1, as used in Mozilla Firefox before 45.0, allows remote attackers to cause a denial of service or possibly h...
CVE-2016-1978
- EPSS 2.75%
- Veröffentlicht 13.03.2016 18:59:27
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspec...
CVE-2016-1977
- EPSS 0.96%
- Veröffentlicht 13.03.2016 18:59:26
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory c...
CVE-2016-1976
- EPSS 0.53%
- Veröffentlicht 13.03.2016 18:59:25
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vect...
CVE-2016-1975
- EPSS 0.59%
- Veröffentlicht 13.03.2016 18:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified ot...
CVE-2016-1974
- EPSS 0.68%
- Veröffentlicht 13.03.2016 18:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-o...