|
267281
|
4.3 |
MEDIUM
Network
|
canonical mozilla opensuse
|
ubuntu_linux firefox leap opensuse
|
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
|
CWE-200
Information Exposure
|
CVE-2016-2832
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267282
|
8.8 |
HIGH
Network
|
canonical mozilla debian opensuse
|
ubuntu_linux firefox debian_linux leap opensuse
|
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (…
|
CWE-254 CWE-284
7PK - Security Features Improper Access Control
|
CVE-2016-2831
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267283
|
6.5 |
MEDIUM
Network
|
canonical mozilla opensuse
|
ubuntu_linux firefox leap opensuse
|
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or…
|
CWE-284
Improper Access Control
|
CVE-2016-2829
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267284
|
8.8 |
HIGH
Network
|
canonical opensuse mozilla debian
|
ubuntu_linux leap opensuse firefox debian_linux
|
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after des…
|
NVD-CWE-Other
|
CVE-2016-2828
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267285
|
7.8 |
HIGH
Local
|
mozilla
|
firefox
|
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local u…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2826
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267286
|
6.5 |
MEDIUM
Network
|
canonical opensuse mozilla
|
ubuntu_linux leap opensuse firefox
|
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
|
CWE-284
Improper Access Control
|
CVE-2016-2825
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267287
|
8.8 |
HIGH
Network
|
mozilla opensuse
|
firefox leap opensuse
|
The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2824
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267288
|
6.5 |
MEDIUM
Network
|
debian mozilla canonical opensuse
|
debian_linux firefox ubuntu_linux leap opensuse
|
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
|
CWE-284
Improper Access Control
|
CVE-2016-2822
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267289
|
7.5 |
HIGH
Network
|
mozilla debian opensuse canonical
|
firefox debian_linux leap opensuse ubuntu_linux
|
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execu…
|
NVD-CWE-Other
|
CVE-2016-2821
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267290
|
8.8 |
HIGH
Network
|
opensuse mozilla debian canonical
|
leap opensuse firefox debian_linux ubuntu_linux
|
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2819
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|