Vulnerabilities > Mozilla > Firefox > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-5399 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
Memory safety bugs were reported in Firefox 51.
network
low complexity
mozilla CWE-119
critical
9.8
2018-06-11 CVE-2017-5400 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks.
network
low complexity
redhat debian mozilla CWE-119
critical
9.8
2018-06-11 CVE-2017-5401 7PK - Errors vulnerability in multiple products
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error.
network
low complexity
debian redhat mozilla CWE-388
critical
9.8
2018-06-11 CVE-2017-5402 Use After Free vulnerability in multiple products
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts.
network
low complexity
debian redhat mozilla CWE-416
critical
9.8
2018-06-11 CVE-2017-5403 Use After Free vulnerability in Mozilla Thunderbird
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object.
network
low complexity
mozilla CWE-416
critical
9.8
2018-06-11 CVE-2017-5404 Use After Free vulnerability in multiple products
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it.
network
low complexity
debian redhat mozilla CWE-416
critical
9.8
2018-06-11 CVE-2017-5410 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup.
network
low complexity
debian redhat mozilla CWE-119
critical
9.8
2018-06-11 CVE-2017-5413 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
A segmentation fault can occur during some bidirectional layout operations.
network
low complexity
mozilla CWE-119
critical
9.8
2018-06-11 CVE-2017-5428 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest.
network
low complexity
redhat mozilla CWE-190
critical
9.8
2018-06-11 CVE-2017-5429 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52.
network
low complexity
redhat debian mozilla CWE-119
critical
9.8