CVE-2017-5435
- EPSS 2.49%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 21.11.2024 03:27:36
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1,...
CVE-2017-5436
- EPSS 1.03%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 21.11.2024 03:27:36
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as well as Mozilla products. This vulnerability affec...
CVE-2017-5438
- EPSS 2.02%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 21.11.2024 03:27:37
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox...
CVE-2017-5439
- EPSS 2.02%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 21.11.2024 03:27:37
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 5...
CVE-2017-5440
- EPSS 2.02%
- Veröffentlicht 11.06.2018 21:29:05
- Zuletzt bearbeitet 21.11.2024 03:27:37
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. T...
CVE-2017-5400
- EPSS 0.57%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:31
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45....
CVE-2017-5401
- EPSS 2.31%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:32
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 4...
CVE-2017-5402
- EPSS 2.66%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:32
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR ...
CVE-2017-5404
- EPSS 23.67%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:32
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 4...
CVE-2017-5405
- EPSS 2.35%
- Veröffentlicht 11.06.2018 21:29:04
- Zuletzt bearbeitet 21.11.2024 03:27:32
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.