Vulnerabilities > Mozilla > Firefox
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2016-5293 | Improper Input Validation vulnerability in multiple products When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. | 5.5 |
2018-06-11 | CVE-2016-5292 | Improper Input Validation vulnerability in Mozilla Firefox During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. | 6.5 |
2018-06-11 | CVE-2016-5291 | Improper Input Validation vulnerability in multiple products A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. | 5.5 |
2018-06-11 | CVE-2016-5290 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4. | 9.8 |
2018-06-11 | CVE-2016-5289 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox Memory safety bugs were reported in Firefox 49. | 9.8 |
2018-06-11 | CVE-2016-5288 | Information Exposure vulnerability in Mozilla Firefox Web content could access information in the HTTP cache if e10s is disabled. | 5.9 |
2018-06-11 | CVE-2016-5287 | Use After Free vulnerability in Mozilla Firefox A potentially exploitable use-after-free crash during actor destruction with service workers. | 9.8 |
2018-05-04 | CVE-2018-10229 | Information Exposure vulnerability in multiple products A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API. | 4.8 |
2017-08-18 | CVE-2007-5341 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8. | 9.8 |
2017-03-15 | CVE-2016-10196 | Out-of-bounds Write vulnerability in multiple products Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument. | 7.5 |