|
250541
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed corre…
|
CWE-20
Improper Input Validation
|
CVE-2017-5395
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250542
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue…
|
CWE-352
Origin Validation Error
|
CVE-2017-5394
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250543
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5393
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250544
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes.…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5392
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250545
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potent…
|
NVD-CWE-noinfo
|
CVE-2017-5391
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250546
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. Thi…
|
CWE-601
Open Redirect
|
CVE-2017-5389
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250547
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
A STUN server in conjunction with a large number of "webkitRTCPeerConnection" objects can be used to send large STUN packets in a short period of time due to a lack of rate limiting being applied on …
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2017-5388
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250548
|
3.3 |
LOW
Local
|
mozilla
|
firefox
|
The existence of a specifically requested local file can be found due to the double firing of the "onerror" when the "source" attribute on a "<track>" tag refers to a file that does not exist if the …
|
CWE-538
File and Directory Information Exposure
|
CVE-2017-5387
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250549
|
7.3 |
HIGH
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus firefox fir…
|
WebExtension scripts can use the "data:" protocol to affect pages loaded by other web extensions using this protocol, leading to potential data disclosure or privilege escalation in affected extensio…
|
NVD-CWE-noinfo
|
CVE-2017-5386
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250550
|
9.8 |
CRITICAL
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux enterprise_linux_server_aus enterprise_linux_server_eus thunderbird
|
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vul…
|
NVD-CWE-noinfo
|
CVE-2017-5390
|
2024-11-21 12:27 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|