|
248121
|
4.3 |
MEDIUM
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_aus enterprise_linux_eus thunderbird
|
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
|
CWE-200
Information Exposure
|
CVE-2017-7847
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248122
|
8.8 |
HIGH
Network
|
redhat debian mozilla
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus debian_linux thunderbird
|
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> defa…
|
CWE-74
Injection
|
CVE-2017-7846
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248123
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the libr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7845
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248124
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow …
|
CWE-200
Information Exposure
|
CVE-2017-7844
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248125
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of …
|
CWE-200
Information Exposure
|
CVE-2017-7842
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248126
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7840
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248127
|
7.5 |
HIGH
Network
|
debian mozilla redhat
|
debian_linux firefox firefox_esr enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode a…
|
CWE-200
Information Exposure
|
CVE-2017-7843
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248128
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
Control characters prepended before "javascript:" URLs pasted in the addressbar can cause the leading characters to be ignored and the pasted JavaScript to be executed instead of being blocked. This …
|
CWE-79
Cross-site Scripting
|
CVE-2017-7839
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248129
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed …
|
CWE-20
Improper Input Validation
|
CVE-2017-7838
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248130
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
SVG loaded through "<img>" tags can use "<meta>" tags within the SVG data to set cookies for that page. This vulnerability affects Firefox < 57.
|
CWE-20
Improper Input Validation
|
CVE-2017-7837
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|