Show filters
93 Total Results
Displaying 61-70 of 93
Sort by:
Attacker Value
Unknown

CVE-2015-4522

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
0
Attacker Value
Unknown

CVE-2015-4505

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.
0
Attacker Value
Unknown

CVE-2015-4520

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* response header.
0
Attacker Value
Unknown

CVE-2015-4506

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.
0
Attacker Value
Unknown

CVE-2015-7175

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors, related to an "overflow."
0
Attacker Value
Unknown

CVE-2015-7180

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
The ReadbackResultWriterD3D11::Run function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 misinterprets the return value of a function call, which might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2015-7176

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
The AnimationThread function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 uses an incorrect argument to the sscanf function, which might allow remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2015-7178

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, mishandles shader access, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted (1) OpenGL or (2) WebGL content.
0
Attacker Value
Unknown

CVE-2015-4517

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
0
Attacker Value
Unknown

CVE-2015-4519

Disclosure Date: September 24, 2015 (last updated October 23, 2024)
Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element.
0