|
257351
|
7.5 |
HIGH
Network
|
debian redhat mozilla torproject
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vu…
|
CWE-416
Use After Free
|
CVE-2016-9079
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257352
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loa…
|
CWE-601
Open Redirect
|
CVE-2016-9078
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257353
|
7.0 |
HIGH
Local
|
mozilla
|
firefox
|
Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the image…
|
CWE-362
Race Condition
|
CVE-2016-9077
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257354
|
5.9 |
MEDIUM
Network
|
mozilla
|
firefox
|
An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulner…
|
CWE-20
Improper Input Validation
|
CVE-2016-9076
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257355
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install addi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9075
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257356
|
5.9 |
MEDIUM
Network
|
mozilla debian
|
firefox thunderbird firefox_esr debian_linux
|
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird …
|
CWE-200
Information Exposure
|
CVE-2016-9074
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257357
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9073
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257358
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and…
|
CWE-254
7PK - Security Features
|
CVE-2016-9072
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257359
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox <…
|
CWE-254
7PK - Security Features
|
CVE-2016-9071
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257360
|
8.0 |
HIGH
Network
|
mozilla
|
firefox
|
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulne…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-9070
|
2024-11-21 12:00 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|