CVE-2017-5407
- EPSS 1.1%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violate...
CVE-2017-5408
- EPSS 1.07%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < ...
CVE-2017-5410
- EPSS 2.66%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52...
CVE-2017-5411
- EPSS 0.74%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:34
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This is...
CVE-2017-5412
- EPSS 0.38%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:34
A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5413
- EPSS 0.59%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:34
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5414
- EPSS 0.13%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:34
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects ...
CVE-2017-5416
- EPSS 0.86%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:34
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5380
- EPSS 1.89%
- Veröffentlicht 11.06.2018 21:29:03
- Zuletzt bearbeitet 25.11.2025 17:50:16
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5383
- EPSS 2.44%
- Veröffentlicht 11.06.2018 21:29:03
- Zuletzt bearbeitet 25.11.2025 17:50:16
URLs containing certain unicode glyphs for alternative hyphens and quotes do not properly trigger punycode display, allowing for domain name spoofing attacks in the location bar. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and ...