Vulnerabilities > Mozilla > Firefox > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2016-9064 | Improper Certificate Validation vulnerability in Mozilla Firefox Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. | 5.9 |
2018-06-11 | CVE-2016-5298 | Improper Input Validation vulnerability in Mozilla Firefox A mechanism where disruption of the loading of a new web page can cause the previous page's favicon and SSL indicator to not be reset when the new page is loaded. | 6.5 |
2018-06-11 | CVE-2016-5294 | Improper Input Validation vulnerability in Mozilla Firefox The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. | 5.5 |
2018-06-11 | CVE-2016-5293 | Improper Input Validation vulnerability in multiple products When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. | 5.5 |
2018-06-11 | CVE-2016-5292 | Improper Input Validation vulnerability in Mozilla Firefox During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. | 6.5 |
2018-06-11 | CVE-2016-5291 | Improper Input Validation vulnerability in multiple products A same-origin policy bypass with local shortcut files to load arbitrary local content from disk. | 5.5 |
2018-06-11 | CVE-2016-5288 | Information Exposure vulnerability in Mozilla Firefox Web content could access information in the HTTP cache if e10s is disabled. | 5.9 |
2018-05-04 | CVE-2018-10229 | Information Exposure vulnerability in multiple products A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API. | 4.8 |
2016-09-22 | CVE-2016-5282 | Information Exposure vulnerability in Mozilla Firefox Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource. | 6.5 |
2016-09-22 | CVE-2016-5279 | Information Exposure vulnerability in Mozilla Firefox Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code. | 4.3 |