|
257191
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox <…
|
CWE-254
7PK - Security Features
|
CVE-2016-9071
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257192
|
8.0 |
HIGH
Network
|
mozilla
|
firefox
|
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulne…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9070
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257193
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.
|
CWE-416
Use After Free
|
CVE-2016-9068
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257194
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
|
CWE-416
Use After Free
|
CVE-2016-9067
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257195
|
7.5 |
HIGH
Network
|
mozilla debian
|
firefox thunderbird firefox_esr debian_linux
|
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9066
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257196
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issu…
|
CWE-20
Improper Input Validation
|
CVE-2016-9065
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257197
|
5.9 |
MEDIUM
Network
|
mozilla
|
firefox firefox_esr
|
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connect…
|
CWE-295
Improper Certificate Validation
|
CVE-2016-9064
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257198
|
9.8 |
CRITICAL
Network
|
mozilla debian python
|
firefox debian_linux python
|
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2016-9063
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257199
|
3.3 |
LOW
Local
|
mozilla
|
firefox
|
Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the Firefox profile after the mode is exited. Note: This issue onl…
|
CWE-200
Information Exposure
|
CVE-2016-9062
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257200
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Fir…
|
CWE-275
Permission Issues
|
CVE-2016-9061
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|