Show filters
517 Total Results
Displaying 211-220 of 517
Sort by:
Attacker Value
Unknown

CVE-2017-5455

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vulnerability that resulted in remote code execution inside the sandboxed process. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.
0
Attacker Value
Unknown

CVE-2017-5428

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.
0
Attacker Value
Unknown

CVE-2018-5091

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability can occur during WebRTC connections when interacting with the DTMF timers. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.6 and Firefox < 58.
0
Attacker Value
Unknown

CVE-2017-5400

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
0
Attacker Value
Unknown

CVE-2017-7751

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
0
Attacker Value
Unknown

CVE-2017-7829

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
It is possible to spoof the sender's email address and display an arbitrary sender address to the email recipient. The real sender's address is not displayed if preceded by a null character in the display string. This vulnerability affects Thunderbird < 52.5.2.
0
Attacker Value
Unknown

CVE-2017-7749

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.
0
Attacker Value
Unknown

CVE-2017-7814

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
File downloads encoded with "blob:" and "data:" URL elements bypassed normal file download checks though the Phishing and Malware Protection feature and its block lists of suspicious sites and files. This would allow malicious sites to lure users into downloading executables that would otherwise be detected as suspicious. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
0
Attacker Value
Unknown

CVE-2017-5448

Disclosure Date: June 11, 2018 (last updated October 22, 2024)
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
0
Attacker Value
Unknown

CVE-2017-5398

Disclosure Date: June 11, 2018 (last updated November 26, 2024)
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
0