Show filters
274 Total Results
Displaying 121-130 of 274
Sort by:
Attacker Value
Unknown
CVE-2017-5407
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
0
Attacker Value
Unknown
CVE-2017-5465
Disclosure Date: June 11, 2018 (last updated October 22, 2024)
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
0
Attacker Value
Unknown
CVE-2017-5390
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
0
Attacker Value
Unknown
CVE-2017-7809
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur when an editor DOM node is deleted prematurely during tree traversal while still bound to the document. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
0
Attacker Value
Unknown
CVE-2017-5440
Disclosure Date: June 11, 2018 (last updated October 22, 2024)
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
0
Attacker Value
Unknown
CVE-2017-5432
Disclosure Date: June 11, 2018 (last updated October 22, 2024)
A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
0
Attacker Value
Unknown
CVE-2017-5464
Disclosure Date: June 11, 2018 (last updated October 22, 2024)
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
0
Attacker Value
Unknown
CVE-2018-5096
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur while editing events in form elements on a page, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Thunderbird < 52.6.
0
Attacker Value
Unknown
CVE-2017-7778
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized memory. These issues were addressed in Graphite 2 version 1.3.10. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
0
Attacker Value
Unknown
CVE-2017-5400
Disclosure Date: June 11, 2018 (last updated November 26, 2024)
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
0