CVE-2016-5262
- EPSS 0.29%
- Published 05.08.2016 01:59:18
- Last modified 12.04.2025 10:46:40
Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote a...
CVE-2016-5259
- EPSS 1.15%
- Published 05.08.2016 01:59:15
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a neste...
CVE-2016-5258
- EPSS 1.06%
- Published 05.08.2016 01:59:14
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of ...
CVE-2016-5254
- EPSS 0.89%
- Published 05.08.2016 01:59:12
- Last modified 12.04.2025 10:46:40
Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application cr...
CVE-2016-5252
- EPSS 1.49%
- Published 05.08.2016 01:59:09
- Last modified 12.04.2025 10:46:40
Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data that is mishandled duri...
CVE-2016-2837
- EPSS 0.22%
- Published 05.08.2016 01:59:03
- Last modified 12.04.2025 10:46:40
Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing...
CVE-2016-5403
- EPSS 0.07%
- Published 02.08.2016 16:59:03
- Last modified 12.04.2025 10:46:40
The virtqueue_pop function in hw/virtio/virtio.c in QEMU allows local guest OS administrators to cause a denial of service (memory consumption and QEMU process crash) by submitting requests without waiting for completion.
CVE-2016-2180
- EPSS 4.2%
- Published 01.08.2016 02:59:11
- Last modified 12.04.2025 10:46:40
The TS_OBJ_print_bio function in crypto/ts/ts_lib.c in the X.509 Public Key Infrastructure Time-Stamp Protocol (TSP) implementation in OpenSSL through 1.0.2h allows remote attackers to cause a denial of service (out-of-bounds read and application cra...
CVE-2016-5444
- EPSS 4.87%
- Published 21.07.2016 10:14:57
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.48 and earlier, 5.6.29 and earlier, and 5.7.11 and earlier and MariaDB before 5.5.49, 10.0.x before 10.0.25, and 10.1.x before 10.1.14 allows remote attackers to affect confidentiality via vectors related...
CVE-2016-5440
- EPSS 0.67%
- Published 21.07.2016 10:14:53
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in Oracle MySQL 5.5.49 and earlier, 5.6.30 and earlier, and 5.7.12 and earlier and MariaDB before 5.5.50, 10.0.x before 10.0.26, and 10.1.x before 10.1.15 allows remote administrators to affect availability via vectors relat...