|
268181
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows rem…
|
CWE-416
Use After Free
|
CVE-2016-5280
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268182
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
|
CWE-200
Information Exposure
|
CVE-2016-5279
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268183
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrar…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5278
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268184
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary co…
|
CWE-416
Use After Free
|
CVE-2016-5277
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268185
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote a…
|
CWE-416
Use After Free
|
CVE-2016-5276
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268186
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interac…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5275
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268187
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute …
|
CWE-416
Use After Free
|
CVE-2016-5274
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268188
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web …
|
CWE-284
Improper Access Control
|
CVE-2016-5273
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268189
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPU…
|
CWE-20
Improper Input Validation
|
CVE-2016-5272
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268190
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conju…
|
CWE-125
Out-of-bounds Read
|
CVE-2016-5271
|
2024-11-21 11:53 |
2016-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|