|
265551
|
8.8 |
HIGH
Network
|
sil mozilla
|
graphite2 firefox
|
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1969
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265552
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli comp…
|
CWE-189
Numeric Errors
|
CVE-2016-1968
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265553
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive inform…
|
CWE-200
Information Exposure
|
CVE-2016-1967
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265554
|
8.8 |
HIGH
Network
|
oracle mozilla opensuse
|
linux firefox thunderbird opensuse
|
The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or ca…
|
NVD-CWE-Other
|
CVE-2016-1966
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265555
|
4.3 |
MEDIUM
Network
|
mozilla opensuse oracle
|
firefox opensuse linux
|
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors invo…
|
CWE-254
7PK - Security Features
|
CVE-2016-1965
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265556
|
8.8 |
HIGH
Network
|
oracle suse opensuse mozilla
|
linux linux_enterprise leap opensuse firefox thunderbird
|
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of se…
|
NVD-CWE-Other
|
CVE-2016-1964
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265557
|
7.4 |
HIGH
Local
|
mozilla
|
firefox
|
The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.
|
CWE-264 CWE-119
Permissions, Privileges, and Access Controls Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1963
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265558
|
9.8 |
CRITICAL
Network
|
mozilla opensuse oracle
|
firefox opensuse linux
|
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by…
|
NVD-CWE-Other
|
CVE-2016-1962
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265559
|
8.8 |
HIGH
Network
|
suse opensuse mozilla oracle
|
linux_enterprise leap opensuse firefox thunderbird linux
|
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute …
|
NVD-CWE-Other
|
CVE-2016-1961
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265560
|
8.8 |
HIGH
Network
|
oracle mozilla suse opensuse
|
linux firefox thunderbird linux_enterprise leap opensuse
|
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause…
|
NVD-CWE-Other
|
CVE-2016-1960
|
2024-11-21 11:47 |
2016-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|