Vulnerabilities > Mozilla > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-06-11 CVE-2017-7796 Improper Input Validation vulnerability in Mozilla Firefox
On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that name.
local
high complexity
mozilla CWE-20
4.7
2018-06-11 CVE-2017-7791 Improper Input Validation vulnerability in multiple products
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content.
network
low complexity
debian redhat mozilla CWE-20
5.3
2018-06-11 CVE-2017-7789 Unspecified vulnerability in Mozilla Firefox
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection.
network
low complexity
mozilla
5.3
2018-06-11 CVE-2017-7782 Improper Privilege Management vulnerability in Mozilla Firefox
An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections.
network
low complexity
mozilla CWE-269
5.3
2018-06-11 CVE-2017-7781 Unspecified vulnerability in Mozilla Firefox
An error occurs in the elliptic curve point addition algorithm that uses mixed Jacobian-affine coordinates where it can yield a result "POINT_AT_INFINITY" when it should not.
network
high complexity
mozilla
5.9
2018-06-11 CVE-2017-7770 Improper Input Validation vulnerability in Mozilla Firefox
A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered.
network
high complexity
mozilla CWE-20
5.9
2018-06-11 CVE-2017-7768 Information Exposure vulnerability in Mozilla Firefox
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater.
local
low complexity
mozilla CWE-200
5.5
2018-06-11 CVE-2017-7767 Improper Privilege Management vulnerability in Mozilla Firefox
The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access.
local
low complexity
mozilla CWE-269
5.5
2018-06-11 CVE-2017-7764 Improper Input Validation vulnerability in multiple products
Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion.
network
low complexity
mozilla debian CWE-20
5.3
2018-06-11 CVE-2017-7763 Improper Input Validation vulnerability in multiple products
Default fonts on OS X display some Tibetan characters as whitespace.
network
low complexity
mozilla debian CWE-20
5.3