|
276401
|
- |
|
mozilla opensuse canonical
|
firefox opensuse ubuntu_linux
|
The QCMS implementation in Mozilla Firefox before 37.0 allows remote attackers to obtain sensitive information from process heap memory or cause a denial of service (out-of-bounds read) via an image …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-0811
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276402
|
- |
|
mozilla
|
firefox
|
Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements assoc…
|
CWE-20
Improper Input Validation
|
CVE-2015-0810
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276403
|
- |
|
opensuse canonical mozilla
|
opensuse ubuntu_linux firefox
|
The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which m…
|
CWE-17
Code
|
CVE-2015-0808
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276404
|
- |
|
mozilla
|
firefox_esr firefox thunderbird
|
The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight reque…
|
CWE-352
Origin Validation Error
|
CVE-2015-0807
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276405
|
- |
|
canonical mozilla opensuse
|
ubuntu_linux firefox opensuse
|
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferT…
|
CWE-17
Code
|
CVE-2015-0806
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276406
|
- |
|
opensuse mozilla canonical
|
opensuse firefox ubuntu_linux
|
The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurfac…
|
CWE-17
Code
|
CVE-2015-0805
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276407
|
- |
|
mozilla opensuse canonical
|
firefox opensuse ubuntu_linux
|
The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which all…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-0804
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276408
|
- |
|
canonical opensuse mozilla
|
ubuntu_linux opensuse firefox
|
The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, w…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-0803
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276409
|
- |
|
opensuse canonical mozilla
|
opensuse ubuntu_linux firefox
|
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-0802
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276410
|
- |
|
mozilla
|
firefox_esr firefox thunderbird
|
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privil…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-0801
|
2024-11-21 11:23 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|