CVE-2016-5291
- EPSS 0.04%
- Veröffentlicht 11.06.2018 21:29:00
- Zuletzt bearbeitet 25.11.2025 17:50:16
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
CVE-2016-5293
- EPSS 0.07%
- Veröffentlicht 11.06.2018 21:29:00
- Zuletzt bearbeitet 25.11.2025 17:50:16
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. This vulnerability requires local system access. Note: this issue only affects Windows operatin...
CVE-2016-5296
- EPSS 2.57%
- Veröffentlicht 11.06.2018 21:29:00
- Zuletzt bearbeitet 25.11.2025 17:50:16
A heap-buffer-overflow in Cairo when processing SVG content caused by compiler optimization, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
CVE-2016-5297
- EPSS 1.82%
- Veröffentlicht 11.06.2018 21:29:00
- Zuletzt bearbeitet 25.11.2025 17:50:16
An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
CVE-2016-9063
- EPSS 2.42%
- Veröffentlicht 11.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:00:31
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
CVE-2018-12020
- EPSS 2.8%
- Veröffentlicht 08.06.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:25
mainproc.c in GnuPG before 2.2.8 mishandles the original filename during decryption and verification actions, which allows remote attackers to spoof the output that GnuPG sends on file descriptor 2 to other programs that use the "--status-fd 2" optio...
CVE-2018-12015
- EPSS 15.07%
- Veröffentlicht 07.06.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:24
In Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and overwrite arbitrary files, via an archive file containing a symlink and a regular file with the same name.
CVE-2017-7653
- EPSS 0.93%
- Veröffentlicht 05.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:23
The Eclipse Mosquitto broker up to version 1.4.15 does not reject strings that are not valid UTF-8. A malicious client could cause other clients that do reject invalid UTF-8 strings to disconnect themselves from the broker by sending a topic string w...
CVE-2017-7654
- EPSS 1.45%
- Veröffentlicht 05.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:32:23
In Eclipse Mosquitto 1.4.15 and earlier, a Memory Leak vulnerability was found within the Mosquitto Broker. Unauthenticated clients can send crafted CONNECT packets which could cause a denial of service in the Mosquitto Broker.
CVE-2018-1000180
- EPSS 0.26%
- Veröffentlicht 05.06.2018 13:29:00
- Zuletzt bearbeitet 12.05.2025 17:37:16
Bouncy Castle BC 1.54 - 1.59, BC-FJA 1.0.0, BC-FJA 1.0.1 and earlier have a flaw in the Low-level interface to RSA key pair generator, specifically RSA Key Pairs generated in low-level API with added certainty may have less M-R tests than expected. T...