Show filters
977 Total Results
Displaying 171-180 of 977
Sort by:
Attacker Value
Unknown

CVE-2017-5400

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
0
Attacker Value
Unknown

CVE-2016-9904

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
0
Attacker Value
Unknown

CVE-2017-5398

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
0
Attacker Value
Unknown

CVE-2017-7791

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
0
Attacker Value
Unknown

CVE-2016-9898

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
0
Attacker Value
Unknown

CVE-2017-5404

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
0
Attacker Value
Unknown

CVE-2017-5375

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
0
Attacker Value
Unknown

CVE-2017-5376

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
0
Attacker Value
Unknown

CVE-2017-7375

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
A flaw in libxml2 allows remote XML entity inclusion with default parser flags (i.e., when the caller did not request entity substitution, DTD validation, external DTD subset loading, or default DTD attributes). Depending on the context, this may expose a higher-risk attack surface in libxml2 not usually reachable with default parser flags, and expose content from local files, HTTP, or FTP servers (which might be otherwise unreachable).
0
Attacker Value
Unknown

CVE-2017-15104

Disclosure Date: December 18, 2017 (last updated November 26, 2024)
An access flaw was found in Heketi 5, where the heketi.json configuration file was world readable. An attacker having local access to the Heketi server could read plain-text passwords from the heketi.json file.