CVE-2015-4508
- EPSS 0.7%
- Veröffentlicht 24.09.2015 04:59:11
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.
CVE-2015-4507
- EPSS 1.2%
- Veröffentlicht 24.09.2015 04:59:10
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbi...
CVE-2015-4506
- EPSS 7.97%
- Veröffentlicht 24.09.2015 04:59:09
- Zuletzt bearbeitet 12.04.2025 10:46:40
Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.
CVE-2015-4505
- EPSS 0.11%
- Veröffentlicht 24.09.2015 04:59:08
- Zuletzt bearbeitet 12.04.2025 10:46:40
updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.
CVE-2015-4504
- EPSS 2.1%
- Veröffentlicht 24.09.2015 04:59:07
- Zuletzt bearbeitet 12.04.2025 10:46:40
The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 pro...
- EPSS 0.58%
- Veröffentlicht 24.09.2015 04:59:06
- Zuletzt bearbeitet 12.04.2025 10:46:40
The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information f...
CVE-2015-4502
- EPSS 0.78%
- Veröffentlicht 24.09.2015 04:59:04
- Zuletzt bearbeitet 12.04.2025 10:46:40
js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.
CVE-2015-4501
- EPSS 2.92%
- Veröffentlicht 24.09.2015 04:59:03
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
CVE-2015-4500
- EPSS 3.17%
- Veröffentlicht 24.09.2015 04:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...
CVE-2015-4476
- EPSS 0.48%
- Veröffentlicht 24.09.2015 04:59:00
- Zuletzt bearbeitet 12.04.2025 10:46:40
Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.