|
248391
|
7.5 |
HIGH
Network
|
eclipse debian
|
jetty debian_linux
|
In Eclipse Jetty, versions 9.2.x and older, 9.3.x (all configurations), and 9.4.x (non-default configuration with RFC2616 compliance enabled), HTTP/0.9 is handled poorly. An HTTP/1 style request line…
|
NVD-CWE-noinfo
|
CVE-2017-7656
|
2024-11-21 12:32 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248392
|
5.3 |
MEDIUM
Network
|
netapp
|
oncommand_unified_manager
|
NetApp OnCommand Unified Manager for 7-Mode (core package) versions prior to 5.2.3 may disclose sensitive LDAP account information to authenticated users when the LDAP authentication configuration is…
|
CWE-200
Information Exposure
|
CVE-2017-7568
|
2024-11-21 12:32 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248393
|
5.3 |
MEDIUM
Network
|
mozilla redhat debian
|
thunderbird enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus debian_linux
|
RSS fields can inject new lines into the created email structure, modifying the message body. This vulnerability affects Thunderbird < 52.5.2.
|
CWE-74
Injection
|
CVE-2017-7848
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248394
|
4.3 |
MEDIUM
Network
|
debian redhat mozilla
|
debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_aus enterprise_linux_eus thunderbird
|
Crafted CSS in an RSS feed can leak and reveal local path strings, which may contain user name. This vulnerability affects Thunderbird < 52.5.2.
|
CWE-200
Information Exposure
|
CVE-2017-7847
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248395
|
8.8 |
HIGH
Network
|
redhat debian mozilla
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus debian_linux thunderbird
|
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> defa…
|
CWE-74
Injection
|
CVE-2017-7846
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248396
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
A buffer overflow occurs when drawing and validating elements using Direct 3D 9 with the ANGLE graphics library, used for WebGL content. This is due to an incorrect value being passed within the libr…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-7845
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248397
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow …
|
CWE-200
Information Exposure
|
CVE-2017-7844
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248398
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of …
|
CWE-200
Information Exposure
|
CVE-2017-7842
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248399
|
6.1 |
MEDIUM
Network
|
mozilla
|
firefox
|
JavaScript can be injected into an exported bookmarks file by placing JavaScript code into user-supplied tags in saved bookmarks. If the resulting exported HTML file is later opened in a browser this…
|
CWE-79
Cross-site Scripting
|
CVE-2017-7840
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248400
|
7.5 |
HIGH
Network
|
debian mozilla redhat
|
debian_linux firefox firefox_esr enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_eus
|
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode a…
|
CWE-200
Information Exposure
|
CVE-2017-7843
|
2024-11-21 12:32 |
2018-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|