Show filters
492 Total Results
Displaying 11-20 of 492
Sort by:
Attacker Value
Unknown
CVE-2018-5800
Disclosure Date: December 07, 2018 (last updated November 27, 2024)
An off-by-one error within the "LibRaw::kodak_ycbcr_load_raw()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.7 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash.
0
Attacker Value
Unknown
CVE-2017-16910
Disclosure Date: December 07, 2018 (last updated November 27, 2024)
An error within the "LibRaw::xtrans_interpolate()" function (internal/dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause an invalid read memory access and subsequently a Denial of Service condition.
0
Attacker Value
Unknown
CVE-2017-16909
Disclosure Date: December 07, 2018 (last updated November 27, 2024)
An error related to the "LibRaw::panasonic_load_raw()" function (dcraw_common.cpp) in LibRaw versions prior to 0.18.6 can be exploited to cause a heap-based buffer overflow and subsequently cause a crash via a specially crafted TIFF image.
0
Attacker Value
Unknown
CVE-2018-12362
Disclosure Date: October 18, 2018 (last updated October 22, 2024)
An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
0
Attacker Value
Unknown
CVE-2018-5187
Disclosure Date: October 18, 2018 (last updated November 27, 2024)
Memory safety bugs present in Firefox 60 and Firefox ESR 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.
0
Attacker Value
Unknown
CVE-2018-12369
Disclosure Date: October 18, 2018 (last updated November 27, 2024)
WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.
0
Attacker Value
Unknown
CVE-2018-12364
Disclosure Date: October 18, 2018 (last updated October 22, 2024)
NPAPI plugins, such as Adobe Flash, can send non-simple cross-origin requests, bypassing CORS by making a same-origin POST that does a 307 redirect to the target site. This allows for a malicious site to engage in cross-site request forgery (CSRF) attacks. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
0
Attacker Value
Unknown
CVE-2018-12366
Disclosure Date: October 18, 2018 (last updated October 22, 2024)
An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
0
Attacker Value
Unknown
CVE-2018-12358
Disclosure Date: October 18, 2018 (last updated November 27, 2024)
Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read responses which are supposed to be opaque. This vulnerability affects Firefox < 61.
0
Attacker Value
Unknown
CVE-2018-12363
Disclosure Date: October 18, 2018 (last updated October 22, 2024)
A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a pointer referencing it. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.
0