Vulnerabilities > Mozilla > Firefox

DATE CVE VULNERABILITY TITLE RISK
2016-09-22 CVE-2016-5281 Use After Free vulnerability in Mozilla Firefox
Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.
network
low complexity
mozilla CWE-416
critical
9.8
2016-09-22 CVE-2016-5280 Use After Free vulnerability in Mozilla Firefox
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.
network
low complexity
mozilla CWE-416
critical
9.8
2016-09-22 CVE-2016-5279 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
network
low complexity
mozilla CWE-200
4.3
2016-09-22 CVE-2016-5278 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.
network
low complexity
mozilla CWE-119
8.8
2016-09-22 CVE-2016-5277 Use After Free vulnerability in Mozilla Firefox
Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.
network
low complexity
mozilla CWE-416
critical
9.8
2016-09-22 CVE-2016-5276 Use After Free vulnerability in Mozilla Firefox
Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute.
network
low complexity
mozilla CWE-416
critical
9.8
2016-09-22 CVE-2016-5275 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.
network
low complexity
mozilla CWE-119
8.8
2016-09-22 CVE-2016-5274 Use After Free vulnerability in Mozilla Firefox
Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between restyling and the Web Animations model implementation.
network
low complexity
mozilla CWE-416
critical
9.8
2016-09-22 CVE-2016-5273 Improper Access Control vulnerability in Mozilla Firefox
The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.
network
low complexity
mozilla CWE-284
8.8
2016-09-22 CVE-2016-5272 Improper Input Validation vulnerability in Mozilla Firefox
The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arbitrary code via a crafted web site.
network
low complexity
mozilla CWE-20
8.8