CVE-2016-1978
- EPSS 2.46%
- Veröffentlicht 13.03.2016 18:59:27
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the ssl3_HandleECDHServerKeyExchange function in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, allows remote attackers to cause a denial of service or possibly have unspec...
CVE-2016-1977
- EPSS 0.7%
- Veröffentlicht 13.03.2016 18:59:26
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory c...
CVE-2016-1976
- EPSS 0.69%
- Veröffentlicht 13.03.2016 18:59:25
- Zuletzt bearbeitet 06.05.2026 22:30:45
Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vect...
CVE-2016-1975
- EPSS 0.59%
- Veröffentlicht 13.03.2016 18:59:24
- Zuletzt bearbeitet 06.05.2026 22:30:45
Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified ot...
CVE-2016-1974
- EPSS 0.49%
- Veröffentlicht 13.03.2016 18:59:23
- Zuletzt bearbeitet 06.05.2026 22:30:45
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-o...
CVE-2016-1973
- EPSS 1%
- Veröffentlicht 13.03.2016 18:59:22
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors.
CVE-2016-1972
- EPSS 0.81%
- Veröffentlicht 13.03.2016 18:59:21
- Zuletzt bearbeitet 06.05.2026 22:30:45
Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.
CVE-2016-1971
- EPSS 0.75%
- Veröffentlicht 13.03.2016 18:59:20
- Zuletzt bearbeitet 06.05.2026 22:30:45
The I420VideoFrame::CreateFrame function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows omits an unspecified status check, which might allow remote attackers to cause a denial of service (memory corruption) or possibly have ot...
CVE-2016-1970
- EPSS 0.75%
- Veröffentlicht 13.03.2016 18:59:19
- Zuletzt bearbeitet 06.05.2026 22:30:45
Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknow...
CVE-2016-1969
- EPSS 0.47%
- Veröffentlicht 13.03.2016 18:59:18
- Zuletzt bearbeitet 06.05.2026 22:30:45
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a cra...