CVE-2017-5434
- EPSS 1.92%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5435
- EPSS 1.77%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1,...
CVE-2017-5436
- EPSS 0.99%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affec...
CVE-2017-5438
- EPSS 1.92%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox...
CVE-2017-5439
- EPSS 1.92%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 5...
CVE-2017-5440
- EPSS 1.92%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. T...
CVE-2017-5400
- EPSS 1%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45....
CVE-2017-5401
- EPSS 2.2%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 4...
CVE-2017-5402
- EPSS 2.5%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 25.11.2025 17:50:16
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR ...
CVE-2017-5403
- EPSS 0.52%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:32
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thun...