|
265501
|
6.5 |
MEDIUM
Network
|
debian mozilla canonical opensuse
|
debian_linux firefox ubuntu_linux leap opensuse
|
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
|
CWE-284
Improper Access Control
|
CVE-2016-2822
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265502
|
7.5 |
HIGH
Network
|
mozilla debian opensuse canonical
|
firefox debian_linux leap opensuse ubuntu_linux
|
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execu…
|
NVD-CWE-Other
|
CVE-2016-2821
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265503
|
8.8 |
HIGH
Network
|
opensuse mozilla debian canonical
|
leap opensuse firefox debian_linux ubuntu_linux
|
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2819
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265504
|
8.8 |
HIGH
Network
|
mozilla debian redhat novell opensuse canonical
|
firefox debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_aus enterprise_linux_for_scientific_computing enterprise_linux_workstation enterpris…
|
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2818
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265505
|
8.8 |
HIGH
Network
|
mozilla canonical novell opensuse
|
firefox_esr ubuntu_linux suse_linux_enterprise_server suse_linux_enterprise_desktop suse_linux_enterprise_software_development_kit leap opensuse firefox
|
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly exe…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2815
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265506
|
5.5 |
MEDIUM
Local
|
google
|
android
|
Activity Manager in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not properly terminate process groups, which allows attackers to obtain sensitive information via a …
|
CWE-200
Information Exposure
|
CVE-2016-2500
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265507
|
5.5 |
MEDIUM
Local
|
google
|
android
|
AudioSource.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 does not initialize certain data, which allows attacker…
|
CWE-200
Information Exposure
|
CVE-2016-2499
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265508
|
5.5 |
MEDIUM
Local
|
google
|
android
|
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to bypass intended data-access restrictions via a crafted application, aka internal bug 27777162.
|
CWE-200
Information Exposure
|
CVE-2016-2498
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265509
|
9.8 |
CRITICAL
Network
|
google
|
android
|
The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially ov…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2016-2496
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265510
|
5.5 |
MEDIUM
Local
|
google
|
android
|
SampleTable.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-06-01 allows remote attackers to cause a denial of service (d…
|
CWE-20
Improper Input Validation
|
CVE-2016-2495
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|