Vulnerabilities > Mozilla > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2016-5295 | Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox This vulnerability allows an attacker to use the Mozilla Maintenance Service to escalate privilege by having the Maintenance Service invoke the Mozilla Updater to run malicious local files. | 7.8 |
2017-12-27 | CVE-2017-11698 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services Heap-based buffer overflow in the __get_page function in lib/dbm/src/h_page.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file. | 7.8 |
2017-12-27 | CVE-2017-11697 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services The __hash_open function in hash.c:229 in Mozilla Network Security Services (NSS) allows context-dependent attackers to cause a denial of service (floating point exception and crash) via a crafted cert8.db file. | 7.8 |
2017-12-27 | CVE-2017-11696 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services Heap-based buffer overflow in the __hash_open function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file. | 7.8 |
2017-12-27 | CVE-2017-11695 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Network Security Services Heap-based buffer overflow in the alloc_segs function in lib/dbm/src/hash.c in Mozilla Network Security Services (NSS) allows context-dependent attackers to have unspecified impact using a crafted cert8.db file. | 7.8 |
2017-05-30 | CVE-2017-7502 | Unspecified vulnerability in Mozilla Network Security Services Null pointer dereference vulnerability in NSS since 3.24.0 was found when server receives empty SSLv2 messages resulting into denial of service by remote attacker. | 7.5 |
2017-03-15 | CVE-2016-10196 | Out-of-bounds Write vulnerability in multiple products Stack-based buffer overflow in the evutil_parse_sockaddr_port function in evutil.c in libevent before 2.1.6-beta allows attackers to cause a denial of service (segmentation fault) via vectors involving a long string in brackets in the ip_as_string argument. | 7.5 |
2016-09-22 | CVE-2016-5284 | Improper Input Validation vulnerability in Mozilla Firefox Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority. | 7.4 |
2016-09-22 | CVE-2016-5283 | Improper Access Control vulnerability in Mozilla Firefox Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized. | 8.8 |
2016-09-22 | CVE-2016-5278 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Mozilla Firefox Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image. | 8.8 |