Vulnerabilities > Mozilla > Firefox > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-7761 Incorrect Default Permissions vulnerability in Mozilla Firefox
The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users.
local
low complexity
mozilla CWE-276
5.5
2018-06-11 CVE-2017-5466 Cross-site Scripting vulnerability in multiple products
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly.
network
low complexity
redhat mozilla CWE-79
6.1
2018-06-11 CVE-2017-5463 Improper Input Validation vulnerability in Mozilla Firefox
Android intents can be used to launch Firefox for Android in reader mode with a user specified URL.
network
low complexity
mozilla CWE-20
5.3
2018-06-11 CVE-2017-5462 Incorrect Calculation vulnerability in multiple products
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over.
network
low complexity
debian mozilla CWE-682
5.3
2018-06-11 CVE-2017-5458 Cross-site Scripting vulnerability in Mozilla Firefox
When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed.
network
low complexity
mozilla CWE-79
6.1
2018-06-11 CVE-2017-5453 Improper Input Validation vulnerability in Mozilla Firefox
A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element.
network
low complexity
mozilla CWE-20
4.3
2018-06-11 CVE-2017-5452 Improper Input Validation vulnerability in Mozilla Firefox
Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected.
network
low complexity
mozilla CWE-20
4.3
2018-06-11 CVE-2017-5451 Improper Input Validation vulnerability in multiple products
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event.
network
low complexity
redhat mozilla CWE-20
4.3
2018-06-11 CVE-2017-5427 Race Condition vulnerability in Mozilla Firefox
A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory.
local
low complexity
mozilla CWE-362
5.5
2018-06-11 CVE-2017-5426 Incorrect Permission Assignment for Critical Resource vulnerability in Mozilla Firefox
On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox.
network
low complexity
mozilla CWE-732
5.3