Show filters
225 Total Results
Displaying 141-150 of 225
Sort by:
Attacker Value
Unknown
CVE-2016-2828
Disclosure Date: June 13, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.
0
Attacker Value
Unknown
CVE-2016-0718
Disclosure Date: May 26, 2016 (last updated November 25, 2024)
Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow.
0
Attacker Value
Unknown
CVE-2016-1947
Disclosure Date: January 31, 2016 (last updated November 25, 2024)
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
0
Attacker Value
Unknown
CVE-2015-7575
Disclosure Date: January 09, 2016 (last updated October 23, 2024)
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
0
Attacker Value
Unknown
CVE-2015-4484
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.
0
Attacker Value
Unknown
CVE-2015-4475
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
0
Attacker Value
Unknown
CVE-2015-4489
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
0
Attacker Value
Unknown
CVE-2015-4492
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.
0
Attacker Value
Unknown
CVE-2015-4473
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
0
Attacker Value
Unknown
CVE-2015-4486
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
The decrease_ref_count function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via malformed WebM video data.
0