CVE-2017-7793
- EPSS 2.57%
- Veröffentlicht 11.06.2018 21:29:09
- Zuletzt bearbeitet 21.11.2024 03:32:40
A use-after-free vulnerability can occur in the Fetch API when the worker or the associated window are freed when still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird...
CVE-2017-7800
- EPSS 4.5%
- Veröffentlicht 11.06.2018 21:29:09
- Zuletzt bearbeitet 21.11.2024 03:32:41
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < ...
CVE-2017-7801
- EPSS 2.44%
- Veröffentlicht 11.06.2018 21:29:09
- Zuletzt bearbeitet 21.11.2024 03:32:41
A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects ...
CVE-2017-7802
- EPSS 2.41%
- Veröffentlicht 11.06.2018 21:29:09
- Zuletzt bearbeitet 21.11.2024 03:32:41
A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements ar...
CVE-2017-7803
- EPSS 1.1%
- Veröffentlicht 11.06.2018 21:29:09
- Zuletzt bearbeitet 21.11.2024 03:32:41
When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVE-2017-7804
- EPSS 0.69%
- Veröffentlicht 11.06.2018 21:29:09
- Zuletzt bearbeitet 21.11.2024 03:32:41
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memor...
CVE-2017-7756
- EPSS 1.97%
- Veröffentlicht 11.06.2018 21:29:08
- Zuletzt bearbeitet 21.11.2024 03:32:35
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2...
CVE-2017-7757
- EPSS 1.97%
- Veröffentlicht 11.06.2018 21:29:08
- Zuletzt bearbeitet 21.11.2024 03:32:36
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and...
CVE-2017-7758
- EPSS 1.77%
- Veröffentlicht 11.06.2018 21:29:08
- Zuletzt bearbeitet 21.11.2024 03:32:36
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
CVE-2017-7763
- EPSS 0.51%
- Veröffentlicht 11.06.2018 21:29:08
- Zuletzt bearbeitet 21.11.2024 03:32:36
Default fonts on OS X display some Tibetan characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating systems. Other operating systems are u...