- EPSS 3.53%
- Veröffentlicht 31.01.2016 18:59:12
- Zuletzt bearbeitet 12.04.2025 10:46:40
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer over...
CVE-2016-1945
- EPSS 0.67%
- Veröffentlicht 31.01.2016 18:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
- EPSS 2.83%
- Veröffentlicht 31.01.2016 18:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2016-1943
- EPSS 0.56%
- Veröffentlicht 31.01.2016 18:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
CVE-2016-1942
- EPSS 0.82%
- Veröffentlicht 31.01.2016 18:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
CVE-2016-1941
- EPSS 0.25%
- Veröffentlicht 31.01.2016 18:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a doub...
CVE-2016-1939
- EPSS 0.58%
- Veröffentlicht 31.01.2016 18:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for ...
CVE-2016-1940
- EPSS 0.32%
- Veröffentlicht 31.01.2016 18:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.
CVE-2016-1938
- EPSS 1.05%
- Veröffentlicht 31.01.2016 18:59:05
- Zuletzt bearbeitet 12.04.2025 10:46:40
The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protecti...
CVE-2016-1937
- EPSS 0.35%
- Veröffentlicht 31.01.2016 18:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.