|
257181
|
5.5 |
MEDIUM
Local
|
joyent
|
smartos
|
An exploitable denial of service exists in the the Joyent SmartOS OS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFSADDENTRIES w…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2016-9040
|
2024-11-21 12:00 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257182
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitra…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-9080
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257183
|
7.5 |
HIGH
Network
|
debian redhat mozilla torproject
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vu…
|
CWE-416
Use After Free
|
CVE-2016-9079
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257184
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loa…
|
CWE-601
Open Redirect
|
CVE-2016-9078
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257185
|
7.0 |
HIGH
Local
|
mozilla
|
firefox
|
Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the image…
|
CWE-362
Race Condition
|
CVE-2016-9077
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257186
|
5.9 |
MEDIUM
Network
|
mozilla
|
firefox
|
An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulner…
|
CWE-20
Improper Input Validation
|
CVE-2016-9076
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257187
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install addi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9075
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257188
|
5.9 |
MEDIUM
Network
|
mozilla debian
|
firefox thunderbird firefox_esr debian_linux
|
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird …
|
CWE-200
Information Exposure
|
CVE-2016-9074
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257189
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9073
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257190
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and…
|
CWE-254
7PK - Security Features
|
CVE-2016-9072
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|