Vulnerabilities > Mozilla > Firefox > 45.1.0

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2016-5293 Improper Input Validation vulnerability in multiple products
When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file.
local
low complexity
mozilla debian CWE-20
5.5
2018-06-11 CVE-2016-5292 Improper Input Validation vulnerability in Mozilla Firefox
During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash.
network
low complexity
mozilla CWE-20
6.5
2018-06-11 CVE-2016-5291 Improper Input Validation vulnerability in multiple products
A same-origin policy bypass with local shortcut files to load arbitrary local content from disk.
local
low complexity
mozilla debian CWE-20
5.5
2018-06-11 CVE-2016-5290 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4.
network
low complexity
mozilla debian CWE-119
critical
9.8
2018-06-11 CVE-2016-5289 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
Memory safety bugs were reported in Firefox 49.
network
low complexity
mozilla CWE-119
critical
9.8
2018-06-11 CVE-2016-5288 Information Exposure vulnerability in Mozilla Firefox
Web content could access information in the HTTP cache if e10s is disabled.
network
high complexity
mozilla CWE-200
5.9
2018-06-11 CVE-2016-5287 Use After Free vulnerability in Mozilla Firefox
A potentially exploitable use-after-free crash during actor destruction with service workers.
network
low complexity
mozilla CWE-416
critical
9.8
2017-03-15 CVE-2016-10196 Out-of-bounds Write vulnerability in multiple products
Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument.
network
low complexity
debian libevent-project mozilla CWE-787
7.5
2016-09-22 CVE-2016-5284 Improper Input Validation vulnerability in Mozilla Firefox
Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.
network
low complexity
mozilla CWE-20
7.4
2016-09-22 CVE-2016-5283 Improper Access Control vulnerability in Mozilla Firefox
Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.
network
low complexity
mozilla CWE-284
8.8