|
266621
|
8.8 |
HIGH
Network
|
canonical mozilla debian opensuse
|
ubuntu_linux firefox debian_linux leap opensuse
|
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (…
|
CWE-254 CWE-284
7PK - Security Features Improper Access Control
|
CVE-2016-2831
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266622
|
6.5 |
MEDIUM
Network
|
canonical mozilla opensuse
|
ubuntu_linux firefox leap opensuse
|
Mozilla Firefox before 47.0 allows remote attackers to spoof permission notifications via a crafted web site that rapidly triggers permission requests, as demonstrated by the microphone permission or…
|
CWE-284
Improper Access Control
|
CVE-2016-2829
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266623
|
8.8 |
HIGH
Network
|
canonical opensuse mozilla debian
|
ubuntu_linux leap opensuse firefox debian_linux
|
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after des…
|
NVD-CWE-Other
|
CVE-2016-2828
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266624
|
7.8 |
HIGH
Local
|
mozilla
|
firefox
|
The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local u…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2826
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266625
|
6.5 |
MEDIUM
Network
|
canonical opensuse mozilla
|
ubuntu_linux leap opensuse firefox
|
Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.
|
CWE-284
Improper Access Control
|
CVE-2016-2825
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266626
|
8.8 |
HIGH
Network
|
mozilla opensuse
|
firefox leap opensuse
|
The TSymbolTableLevel class in ANGLE, as used in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows, allows remote attackers to cause a denial of service (out-of-bounds write and…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2824
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266627
|
6.5 |
MEDIUM
Network
|
debian mozilla canonical opensuse
|
debian_linux firefox ubuntu_linux leap opensuse
|
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu.
|
CWE-284
Improper Access Control
|
CVE-2016-2822
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266628
|
7.5 |
HIGH
Network
|
mozilla debian opensuse canonical
|
firefox debian_linux leap opensuse ubuntu_linux
|
Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execu…
|
NVD-CWE-Other
|
CVE-2016-2821
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266629
|
8.8 |
HIGH
Network
|
opensuse mozilla debian canonical
|
leap opensuse firefox debian_linux ubuntu_linux
|
Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2819
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266630
|
8.8 |
HIGH
Network
|
mozilla debian redhat novell opensuse canonical
|
firefox debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_server_aus enterprise_linux_for_scientific_computing enterprise_linux_workstation enterpris…
|
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2818
|
2024-11-21 11:48 |
2016-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|