Vulnerabilities > Mozilla > Critical

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2016-9063 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow during the parsing of XML using the Expat library.
network
low complexity
mozilla debian python CWE-190
critical
9.8
2018-06-11 CVE-2016-5297 Integer Overflow or Wraparound vulnerability in multiple products
An error in argument length checking in JavaScript, leading to potential integer overflows or other bounds checking issues.
network
low complexity
mozilla debian CWE-190
critical
9.8
2018-06-11 CVE-2016-5290 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Memory safety bugs were reported in Firefox 49 and Firefox ESR 45.4.
network
low complexity
mozilla debian CWE-119
critical
9.8
2018-06-11 CVE-2016-5289 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
Memory safety bugs were reported in Firefox 49.
network
low complexity
mozilla CWE-119
critical
9.8
2018-06-11 CVE-2016-5287 Use After Free vulnerability in Mozilla Firefox
A potentially exploitable use-after-free crash during actor destruction with service workers.
network
low complexity
mozilla CWE-416
critical
9.8
2018-03-07 CVE-2018-7753 Improper Input Validation vulnerability in Mozilla Bleach 2.1/2.1.1/2.1.2
An issue was discovered in Bleach 2.1.x before 2.1.3.
network
low complexity
mozilla CWE-20
critical
9.8
2017-08-18 CVE-2007-5341 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox
Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.
network
low complexity
mozilla CWE-119
critical
9.8
2017-05-11 CVE-2017-5461 Out-of-bounds Write vulnerability in Mozilla Network Security Services
Mozilla Network Security Services (NSS) before 3.21.4, 3.22.x through 3.28.x before 3.28.4, 3.29.x before 3.29.5, and 3.30.x before 3.30.1 allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact by leveraging incorrect base64 operations.
network
low complexity
mozilla CWE-787
critical
9.8
2016-09-22 CVE-2016-5281 Use After Free vulnerability in Mozilla Firefox
Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.
network
low complexity
mozilla CWE-416
critical
9.8
2016-09-22 CVE-2016-5280 Use After Free vulnerability in Mozilla Firefox
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.
network
low complexity
mozilla CWE-416
critical
9.8