Show filters
356 Total Results
Displaying 51-60 of 356
Sort by:
Attacker Value
Unknown

CVE-2016-2799

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-1974

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
0
Attacker Value
Unknown

CVE-2016-2795

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-1962

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
0
Attacker Value
Unknown

CVE-2016-1966

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference and memory corruption) via a crafted NPAPI plugin.
0
Attacker Value
Unknown

CVE-2016-1954

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.
0
Attacker Value
Unknown

CVE-2016-1958

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
0
Attacker Value
Unknown

CVE-2016-1964

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.
0
Attacker Value
Unknown

CVE-2016-2802

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The graphite2::TtfUtil::CmapSubtable4NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-1957

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
0