CVE-2016-7152
- EPSS 1.25%
- Veröffentlicht 06.09.2016 10:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-par...
CVE-2016-5268
- EPSS 0.44%
- Veröffentlicht 05.08.2016 01:59:24
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonst...
CVE-2016-5267
- EPSS 0.37%
- Veröffentlicht 05.08.2016 01:59:23
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set.
CVE-2016-5266
- EPSS 0.43%
- Veröffentlicht 05.08.2016 01:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site.
CVE-2016-5265
- EPSS 0.26%
- Veröffentlicht 05.08.2016 01:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML docu...
CVE-2016-5264
- EPSS 1.01%
- Veröffentlicht 05.08.2016 01:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corru...
CVE-2016-5263
- EPSS 0.68%
- Veröffentlicht 05.08.2016 01:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confu...
CVE-2016-5262
- EPSS 0.29%
- Veröffentlicht 05.08.2016 01:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote a...
CVE-2016-5261
- EPSS 0.69%
- Veröffentlicht 05.08.2016 01:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 and Firefox ESR < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets th...
CVE-2016-5260
- EPSS 0.61%
- Veröffentlicht 05.08.2016 01:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.