|
248041
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could …
|
CWE-200
Information Exposure
|
CVE-2017-5425
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248042
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer …
|
CWE-20
Improper Input Validation
|
CVE-2017-5422
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248043
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is currently loaded. This vulnerability affects Firefox < …
|
CWE-20
Improper Input Validation
|
CVE-2017-5421
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248044
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious pag…
|
CWE-20
Improper Input Validation
|
CVE-2017-5420
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248045
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown through the operating system. This is a denial of servi…
|
NVD-CWE-noinfo
|
CVE-2017-5419
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248046
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory containing matches to specifically set …
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5418
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248047
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
When dragging content from the primary browser pane to the addressbar on a malicious site, it is possible to change the addressbar so that the displayed location following navigation does not match t…
|
CWE-20
Improper Input Validation
|
CVE-2017-5417
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248048
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability affects Firefox < 52 and Thunderbird < 5…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-5416
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248049
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Fi…
|
CWE-20
Improper Input Validation
|
CVE-2017-5415
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248050
|
5.5 |
MEDIUM
Local
|
mozilla
|
firefox thunderbird
|
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or …
|
CWE-200
Information Exposure
|
CVE-2017-5414
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|