Show filters
112 Total Results
Displaying 91-100 of 112
Sort by:
Attacker Value
Unknown
CVE-2015-4485
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Heap-based buffer overflow in the resize_context_buffers function in libvpx in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via malformed WebM video data.
0
Attacker Value
Unknown
CVE-2015-4480
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.
0
Attacker Value
Unknown
CVE-2015-4478
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.
0
Attacker Value
Unknown
CVE-2015-4481
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.
0
Attacker Value
Unknown
CVE-2015-4493
Disclosure Date: August 16, 2015 (last updated October 23, 2024)
Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.
0
Attacker Value
Unknown
CVE-2015-2741
Disclosure Date: July 06, 2015 (last updated October 23, 2024)
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.
0
Attacker Value
Unknown
CVE-2015-2734
Disclosure Date: July 06, 2015 (last updated October 23, 2024)
The CairoTextureClientD3D9::BorrowDrawTarget function in the Direct3D 9 implementation in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 reads data from uninitialized memory locations, which has unspecified impact and attack vectors.
0
Attacker Value
Unknown
CVE-2015-2733
Disclosure Date: July 06, 2015 (last updated October 23, 2024)
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 allows remote attackers to execute arbitrary code via vectors involving attachment of an XMLHttpRequest object to a dedicated worker.
0
Attacker Value
Unknown
CVE-2015-2735
Disclosure Date: July 06, 2015 (last updated October 23, 2024)
nsZipArchive.cpp in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which allows remote attackers to have an unspecified impact via a crafted ZIP archive.
0
Attacker Value
Unknown
CVE-2015-2729
Disclosure Date: July 06, 2015 (last updated October 23, 2024)
The AudioParamTimeline::AudioNodeInputValue function in the Web Audio implementation in Mozilla Firefox before 39.0 and Firefox ESR 38.x before 38.1 does not properly calculate an oscillator rendering range, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.
0