Show filters
550 Total Results
Displaying 121-130 of 550
Sort by:
Attacker Value
Unknown
CVE-2018-10850
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this flaw to trigger a denial of service.
0
Attacker Value
Unknown
CVE-2018-11806
Disclosure Date: June 13, 2018 (last updated November 26, 2024)
m_cat in slirp/mbuf.c in Qemu has a heap-based buffer overflow via incoming fragmented datagrams.
0
Attacker Value
Unknown
CVE-2017-5472
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
0
Attacker Value
Unknown
CVE-2016-9900
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
0
Attacker Value
Unknown
CVE-2017-7846
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
0
Attacker Value
Unknown
CVE-2018-5158
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.
0
Attacker Value
Unknown
CVE-2016-9895
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
0
Attacker Value
Unknown
CVE-2018-5130
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.
0
Attacker Value
Unknown
CVE-2017-7800
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
0
Attacker Value
Unknown
CVE-2017-5378
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash codes, and also allows for data leakage of an object's content using these hash codes. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
0