CVE-2017-5438
- EPSS 2.02%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox...
CVE-2017-5439
- EPSS 2.02%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 5...
CVE-2017-5440
- EPSS 2.02%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. T...
CVE-2017-5400
- EPSS 1.05%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45....
CVE-2017-5401
- EPSS 2.31%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 4...
CVE-2017-5402
- EPSS 2.66%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR ...
CVE-2017-5403
- EPSS 0.54%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:32
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thun...
CVE-2017-5404
- EPSS 23.67%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 4...
CVE-2017-5405
- EPSS 2.35%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
CVE-2017-5406
- EPSS 0.74%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:32
A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52.