- EPSS 3.53%
- Published 31.01.2016 18:59:12
- Last modified 12.04.2025 10:46:40
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer over...
CVE-2016-1945
- EPSS 0.67%
- Published 31.01.2016 18:59:11
- Last modified 12.04.2025 10:46:40
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
- EPSS 2.83%
- Published 31.01.2016 18:59:10
- Last modified 12.04.2025 10:46:40
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2016-1943
- EPSS 0.56%
- Published 31.01.2016 18:59:09
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
CVE-2016-1942
- EPSS 0.82%
- Published 31.01.2016 18:59:08
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.
CVE-2016-1939
- EPSS 0.58%
- Published 31.01.2016 18:59:06
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for ...
CVE-2016-1938
- EPSS 1.05%
- Published 31.01.2016 18:59:05
- Last modified 12.04.2025 10:46:40
The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protecti...
CVE-2016-1937
- EPSS 0.35%
- Published 31.01.2016 18:59:04
- Last modified 12.04.2025 10:46:40
The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
CVE-2016-1935
- EPSS 0.53%
- Published 31.01.2016 18:59:03
- Last modified 12.04.2025 10:46:40
Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
CVE-2016-1933
- EPSS 0.78%
- Published 31.01.2016 18:59:02
- Last modified 12.04.2025 10:46:40
Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted GIF image.