Show filters
505 Total Results
Displaying 71-80 of 505
Sort by:
Attacker Value
Unknown

CVE-2016-2851

Disclosure Date: April 07, 2016 (last updated November 25, 2024)
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via a series of large OTR messages, which triggers a heap-based buffer overflow.
0
Attacker Value
Unknown

CVE-2016-2801

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The graphite2::TtfUtil::CmapSubtable12Lookup function in TtfUtil.cpp in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font, a different vulnerability than CVE-2016-2797.
0
Attacker Value
Unknown

CVE-2016-2794

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The graphite2::TtfUtil::CmapSubtable12NextCodepoint function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service (buffer over-read) or possibly have unspecified other impact via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-2796

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in the graphite2::vm::Machine::Code::Code function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-2799

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Heap-based buffer overflow in the graphite2::Slot::setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted Graphite smart font.
0
Attacker Value
Unknown

CVE-2016-1974

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
0
Attacker Value
Unknown

CVE-2016-1962

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
0
Attacker Value
Unknown

CVE-2016-1966

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference and memory corruption) via a crafted NPAPI plugin.
0
Attacker Value
Unknown

CVE-2016-1954

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.
0
Attacker Value
Unknown

CVE-2016-2795

Disclosure Date: March 13, 2016 (last updated October 23, 2024)
The graphite2::FileFace::get_table_fn function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, does not initialize memory for an unspecified data structure, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted Graphite smart font.
0