Vulnerabilities > Mozilla > Firefox > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2017-7761 | Incorrect Default Permissions vulnerability in Mozilla Firefox The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. | 5.5 |
2018-06-11 | CVE-2017-5466 | Cross-site Scripting vulnerability in multiple products If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. | 6.1 |
2018-06-11 | CVE-2017-5463 | Improper Input Validation vulnerability in Mozilla Firefox Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. | 5.3 |
2018-06-11 | CVE-2017-5462 | Incorrect Calculation vulnerability in multiple products A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. | 5.3 |
2018-06-11 | CVE-2017-5458 | Cross-site Scripting vulnerability in Mozilla Firefox When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. | 6.1 |
2018-06-11 | CVE-2017-5453 | Improper Input Validation vulnerability in Mozilla Firefox A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. | 4.3 |
2018-06-11 | CVE-2017-5452 | Improper Input Validation vulnerability in Mozilla Firefox Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. | 4.3 |
2018-06-11 | CVE-2017-5451 | Improper Input Validation vulnerability in multiple products A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. | 4.3 |
2018-06-11 | CVE-2017-5427 | Race Condition vulnerability in Mozilla Firefox A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. | 5.5 |
2018-06-11 | CVE-2017-5426 | Incorrect Permission Assignment for Critical Resource vulnerability in Mozilla Firefox On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. | 5.3 |