|
247971
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5393
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247972
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes.…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5392
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247973
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potent…
|
NVD-CWE-noinfo
|
CVE-2017-5391
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247974
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. Thi…
|
CWE-601
Open Redirect
|
CVE-2017-5389
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247975
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-5388
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247976
|
3.3 |
LOW
Local
|
mozilla
|
firefox
|
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the …
|
CWE-538
File and Directory Information Exposure
|
CVE-2017-5387
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247977
|
7.3 |
HIGH
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus firefox fir…
|
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensio…
|
NVD-CWE-noinfo
|
CVE-2017-5386
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247978
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vul…
|
NVD-CWE-noinfo
|
CVE-2017-5390
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247979
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to potential information disclosure for sites using thi…
|
CWE-200
Information Exposure
|
CVE-2017-5385
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247980
|
5.9 |
MEDIUM
Network
|
mozilla
|
firefox
|
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information than would be sent to the proxy itself in the case of…
|
CWE-200
Information Exposure
|
CVE-2017-5384
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|