Vulnerabilities > Mozilla > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-01-31 CVE-2016-1941 Cross-site Scripting vulnerability in multiple products
The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
network
low complexity
apple mozilla CWE-79
6.1
2016-01-31 CVE-2016-1940 Code vulnerability in multiple products
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via a data: URL that is mishandled during (1) shortcut opening or (2) BOOKMARK intent processing.
network
low complexity
google mozilla CWE-17
5.3
2016-01-31 CVE-2016-1939 Information Exposure vulnerability in multiple products
Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.
network
low complexity
opensuse mozilla CWE-200
5.3
2016-01-31 CVE-2016-1938 Cryptographic Issues vulnerability in multiple products
The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.
network
low complexity
opensuse mozilla CWE-310
6.5
2016-01-31 CVE-2016-1937 Cross-site Scripting vulnerability in multiple products
The protocol-handler dialog in Mozilla Firefox before 44.0 allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.
network
low complexity
mozilla opensuse CWE-79
6.1
2016-01-31 CVE-2016-1933 Numeric Errors vulnerability in multiple products
Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted GIF image.
network
low complexity
opensuse mozilla CWE-189
6.5
2016-01-09 CVE-2015-8512 Improper Access Control vulnerability in Mozilla Firefox OS 2.2
The lockscreen feature in Mozilla Firefox OS before 2.5 does not properly restrict failed authentication attempts, which makes it easier for physically proximate attackers to obtain access by entering many passcode guesses.
low complexity
mozilla CWE-284
4.6
2016-01-09 CVE-2015-8511 Race Condition vulnerability in Mozilla Firefox OS 2.2
Race condition in the lockscreen feature in Mozilla Firefox OS before 2.5 allows physically proximate attackers to bypass an intended passcode requirement via unspecified vectors.
high complexity
mozilla CWE-362
6.4
2016-01-09 CVE-2015-8510 Cross-site Scripting vulnerability in Mozilla Firefox OS 2.2
Cross-site scripting (XSS) vulnerability in the internationalization feature in the default homescreen app in Mozilla Firefox OS before 2.5 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted web site that is mishandled during "Add to home screen" bookmarking.
network
low complexity
mozilla CWE-79
6.1
2016-01-09 CVE-2015-7575 Data Processing Errors vulnerability in multiple products
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
network
high complexity
mozilla opensuse canonical CWE-19
5.9