Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-04-30 CVE-2016-2820 Improper Access Control vulnerability in Mozilla Firefox
The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.
network
mozilla CWE-284
4.3
2016-04-30 CVE-2016-2817 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.
network
mozilla CWE-264
4.3
2016-04-30 CVE-2016-2816 Improper Access Control vulnerability in Mozilla Firefox
Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.
network
mozilla CWE-284
4.3
2016-04-30 CVE-2016-2813 Information Exposure vulnerability in Mozilla Firefox
Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.
4.3
2016-04-30 CVE-2016-2812 Race Condition vulnerability in Mozilla Firefox
Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.
network
high complexity
mozilla CWE-362
5.1
2016-04-30 CVE-2016-2811 Unspecified vulnerability in Mozilla Firefox
Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.
network
mozilla
6.8
2016-04-30 CVE-2016-2810 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.
4.3
2016-04-30 CVE-2016-2809 Permissions, Privileges, and Access Controls vulnerability in Mozilla Firefox
The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.
5.8
2016-04-30 CVE-2016-1343 XML External Entity Denial of Service vulnerability in Cisco Information Server 6.2Base
The XML parser in Cisco Information Server (CIS) 6.2 allows remote attackers to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, aka Bug ID CSCuy39059.
network
low complexity
cisco
6.4
2016-04-30 CVE-2016-1201 Cross-Site Request Forgery (CSRF) vulnerability in Lockon Ec-Cube
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 3.0.0 through 3.0.9 allows remote attackers to hijack the authentication of administrators.
network
lockon CWE-352
6.8