Vulnerabilities > Mozilla > Thunderbird > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-06-11 | CVE-2017-7791 | Improper Input Validation vulnerability in multiple products On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. | 5.3 |
2018-06-11 | CVE-2017-7782 | Improper Privilege Management vulnerability in Mozilla Firefox An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. | 5.3 |
2018-06-11 | CVE-2017-7764 | Improper Input Validation vulnerability in multiple products Characters from the "Canadian Syllabics" unicode block can be mixed with characters from other unicode blocks in the addressbar instead of being rendered as their raw "punycode" form, allowing for domain name spoofing attacks through character confusion. | 5.3 |
2018-06-11 | CVE-2017-7763 | Improper Input Validation vulnerability in multiple products Default fonts on OS X display some Tibetan characters as whitespace. | 5.3 |
2018-06-11 | CVE-2017-5466 | Cross-site Scripting vulnerability in multiple products If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. | 6.1 |
2018-06-11 | CVE-2017-5462 | Incorrect Calculation vulnerability in multiple products A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. | 5.3 |
2018-06-11 | CVE-2017-5451 | Improper Input Validation vulnerability in multiple products A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. | 4.3 |
2018-06-11 | CVE-2017-5426 | Incorrect Permission Assignment for Critical Resource vulnerability in Mozilla Firefox On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. | 5.3 |
2018-06-11 | CVE-2017-5418 | Out-of-bounds Read vulnerability in Mozilla Firefox An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory containing matches to specifically set patterns. | 5.3 |
2018-06-11 | CVE-2017-5414 | Information Exposure vulnerability in Mozilla Firefox The file picker dialog can choose and display the wrong local default directory when instantiated. | 5.5 |