Vulnerabilities > Mozilla > Firefox ESR
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2017-5470 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. | 9.8 |
2018-06-11 | CVE-2017-5469 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. | 9.8 |
2018-06-11 | CVE-2017-5467 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. | 7.5 |
2018-06-11 | CVE-2017-5466 | Cross-site Scripting vulnerability in multiple products If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. | 6.1 |
2018-06-11 | CVE-2017-5465 | Out-of-bounds Read vulnerability in multiple products An out-of-bounds read while processing SVG content in "ConvolvePixel". | 9.1 |
2018-06-11 | CVE-2017-5462 | Incorrect Calculation vulnerability in multiple products A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. | 5.3 |
2018-06-11 | CVE-2017-5460 | Use After Free vulnerability in multiple products A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. | 9.8 |
2018-06-11 | CVE-2017-5459 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. | 9.8 |
2018-06-11 | CVE-2017-5456 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. | 9.8 |
2018-06-11 | CVE-2017-5455 | The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vulnerability that resulted in remote code execution inside the sandboxed process. | 7.5 |