Vulnerabilities > Mozilla > Firefox > 2.0.0.12

DATE CVE VULNERABILITY TITLE RISK
2015-08-16 CVE-2015-4480 Numeric Errors vulnerability in multiple products
Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.
network
canonical opensuse mozilla CWE-189
critical
9.3
2015-08-16 CVE-2015-4479 Numeric Errors vulnerability in multiple products
Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.
network
low complexity
mozilla canonical opensuse CWE-189
critical
10.0
2015-08-16 CVE-2015-4478 Information Exposure vulnerability in multiple products
Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.
network
low complexity
canonical opensuse mozilla CWE-200
5.0
2015-08-16 CVE-2015-4477 Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.
network
low complexity
canonical opensuse mozilla
critical
10.0
2015-08-16 CVE-2015-4475 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.
network
low complexity
mozilla canonical opensuse CWE-119
7.5
2015-08-16 CVE-2015-4474 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
network
low complexity
canonical opensuse mozilla
critical
10.0
2015-08-16 CVE-2015-4473 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
network
low complexity
canonical debian opensuse mozilla CWE-119
critical
10.0
2015-08-08 CVE-2015-4495 The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.
network
low complexity
mozilla oracle canonical redhat suse opensuse
8.8
2015-07-06 CVE-2015-2742 Information Exposure vulnerability in multiple products
Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.
4.3
2015-07-06 CVE-2015-2741 Cryptographic Issues vulnerability in multiple products
Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.
4.3