|
248921
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a poten…
|
CWE-416
Use After Free
|
CVE-2017-5433
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248922
|
9.8 |
CRITICAL
Network
|
redhat debian mozilla
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server debian_linux thunderbird firefox firefox_esr
|
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort th…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5429
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248923
|
9.8 |
CRITICAL
Network
|
redhat mozilla
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus firefox firefox_esr
|
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This functio…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-5428
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248924
|
5.5 |
MEDIUM
Local
|
mozilla
|
firefox
|
A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced f…
|
CWE-362
Race Condition
|
CVE-2017-5427
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248925
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox thunderbird
|
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-5426
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248926
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could …
|
CWE-200
Information Exposure
|
CVE-2017-5425
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248927
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
If a malicious site uses the "view-source:" protocol in a series within a single hyperlink, it can trigger a non-exploitable browser crash when the hyperlink is selected. This was fixed by no longer …
|
CWE-20
Improper Input Validation
|
CVE-2017-5422
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248928
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
A malicious site could spoof the contents of the print preview window if popup windows are enabled, resulting in user confusion of what site is currently loaded. This vulnerability affects Firefox < …
|
CWE-20
Improper Input Validation
|
CVE-2017-5421
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248929
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious pag…
|
CWE-20
Improper Input Validation
|
CVE-2017-5420
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248930
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
If a malicious site repeatedly triggers a modal authentication prompt, eventually the browser UI will become non-responsive, requiring shutdown through the operating system. This is a denial of servi…
|
NVD-CWE-noinfo
|
CVE-2017-5419
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|