CSV
14,739 results for "vulnerability" Page 71
CVE-2017-5375 CRITICAL

JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 13 affected product(s) NVD
9.8
CVSS
33.5%
EPSS
⚡ 49.3
CVE-2016-9899 CRITICAL

Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

Jun 11, 2018 22 affected product(s) NVD
9.8
CVSS
21.1%
EPSS
⚡ 45.5
CVE-2017-5404 CRITICAL

A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
17.3%
EPSS
⚡ 44.4
CVE-2016-9063 CRITICAL

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

Jun 11, 2018 9 affected product(s) NVD
9.8
CVSS
5.5%
EPSS
⚡ 40.8
CVE-2017-5390 CRITICAL

The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
3.9%
EPSS
⚡ 40.4
CVE-2017-5396 CRITICAL

A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
4.1%
EPSS
⚡ 40.4
CVE-2016-9898 CRITICAL

Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
3.5%
EPSS
⚡ 40.3
CVE-2017-5398 CRITICAL

Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Jun 11, 2018 20 affected product(s) NVD
9.8
CVSS
3.7%
EPSS
⚡ 40.3
CVE-2017-5400 CRITICAL

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Jun 11, 2018 18 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-5433 CRITICAL

A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Jun 11, 2018 18 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-5434 CRITICAL

A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Jun 11, 2018 11 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-5438 CRITICAL

A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Jun 11, 2018 18 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-5439 CRITICAL

A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Jun 11, 2018 18 affected product(s) NVD
9.8
CVSS
3.6%
EPSS
⚡ 40.3
CVE-2017-5373 CRITICAL

Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 13 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-5376 CRITICAL

Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-5380 CRITICAL

A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-5397 CRITICAL

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.

Jun 11, 2018 1 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-5410 CRITICAL

Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Jun 11, 2018 21 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2
CVE-2017-5428 CRITICAL

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

Jun 11, 2018 11 affected product(s) NVD
9.8
CVSS
3.2%
EPSS
⚡ 40.2
CVE-2017-5429 CRITICAL

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

Jun 11, 2018 11 affected product(s) NVD
9.8
CVSS
3.4%
EPSS
⚡ 40.2