Vulnerabilities > Opensuse > Leap > Critical

DATE CVE VULNERABILITY TITLE RISK
2016-01-31 CVE-2016-1931 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 44.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to uninitialized memory encountered during brotli data compression, and other vectors.
network
low complexity
mozilla opensuse CWE-119
critical
10.0
2016-01-31 CVE-2016-1944 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
network
low complexity
mozilla opensuse CWE-119
critical
9.8
2016-01-31 CVE-2016-1946 Numeric Errors vulnerability in multiple products
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.
network
low complexity
opensuse mozilla CWE-189
critical
9.8