CVE-2013-5596
- EPSS 1.78%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly determine the thread for release of an image object, which allows remote attac...
- EPSS 3.63%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the nsDocLoader::doStopDocumentLoad function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22...
CVE-2013-5598
- EPSS 0.78%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
PDF.js in Mozilla Firefox before 25.0 and Firefox ESR 24.x before 24.1 does not properly handle the appending of an IFRAME element, which allows remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges by u...
- EPSS 2.86%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the nsIPresShell::GetPresContext function in the PresShell (aka presentation shell) implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderb...
- EPSS 2.69%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the nsIOService::NewChannelFromURIWithProxyFlags function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonke...
- EPSS 2.86%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the nsEventListenerManager::SetEventHandler function in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey bef...
- EPSS 3.23%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Worker::SetEventListener function in the Web workers implementation in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 allo...
- EPSS 5.27%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
Use-after-free vulnerability in the nsContentUtils::ContentIsHostIncludingDescendantOf function in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to execute arbitr...
CVE-2013-5604
- EPSS 6.86%
- Veröffentlicht 30.10.2013 10:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The txXPathNodeUtils::getBaseURI function in the XSLT processor in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not pro...
- EPSS 0.83%
- Veröffentlicht 01.05.2012 10:12:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The Inter-process Communication (IPC) implementation in Google Chrome before 18.0.1025.168, as used in Mozilla Firefox before 38.0 and other products, does not properly validate messages, which has unspecified impact and attack vectors.