CVE-2015-7174
- EPSS 1.54%
- Veröffentlicht 24.09.2015 04:59:22
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via...
CVE-2015-4522
- EPSS 1.54%
- Veröffentlicht 24.09.2015 04:59:21
- Zuletzt bearbeitet 12.04.2025 10:46:40
The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact v...
CVE-2015-4521
- EPSS 1.54%
- Veröffentlicht 24.09.2015 04:59:20
- Zuletzt bearbeitet 12.04.2025 10:46:40
The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknow...
CVE-2015-4520
- EPSS 0.26%
- Veröffentlicht 24.09.2015 04:59:19
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* re...
CVE-2015-4519
- EPSS 0.21%
- Veröffentlicht 24.09.2015 04:59:18
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an...
CVE-2015-4517
- EPSS 1.54%
- Veröffentlicht 24.09.2015 04:59:17
- Zuletzt bearbeitet 12.04.2025 10:46:40
NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2015-4516
- EPSS 1.01%
- Veröffentlicht 24.09.2015 04:59:16
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page ...
CVE-2015-4512
- EPSS 1.12%
- Veröffentlicht 24.09.2015 04:59:15
- Zuletzt bearbeitet 12.04.2025 10:46:40
gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensit...
CVE-2015-4511
- EPSS 3.15%
- Veröffentlicht 24.09.2015 04:59:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.
CVE-2015-4510
- EPSS 1.1%
- Veröffentlicht 24.09.2015 04:59:13
- Zuletzt bearbeitet 12.04.2025 10:46:40
Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction betwe...