VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2018-5177HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.04

    A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow and crash if it occurs. This vulnerability affects Firefox < 60.

  • CVE-2018-5174HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartScreen will not prompt the user…

  • CVE-2018-5166HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

  • CVE-2018-5160HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.03

    WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.

  • CVE-2018-5157HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects…

  • CVE-2018-5153HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating server in response. This vulnerability affects Firefox < 60.

  • CVE-2018-5137HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A legacy extension's non-contentaccessible, defined resources can be loaded by an arbitrary web page through script. This script does this by using a maliciously crafted path string to reference the resources. Note: this vulnerability does not affect WebExtensions. This…

  • CVE-2018-5136HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A shared worker created from a "data:" URL in one tab can be shared by another tab with a different origin, bypassing the same-origin policy. This vulnerability affects Firefox < 59.

  • CVE-2018-5135HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    WebExtensions can bypass normal restrictions in some circumstances and use "browser.tabs.executeScript" to inject scripts into contexts where this should not be allowed, such as pages from other WebExtensions or unprivileged "about:" pages. This vulnerability affects Firefox <…

  • CVE-2018-5134HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    WebExtensions may use "view-source:" URLs to view local "file:" URL content, as well as content stored in "about:cache", bypassing restrictions that only allow WebExtensions to view specific content. This vulnerability affects Firefox < 59.

  • CVE-2018-5115HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    If an HTTP authentication prompt is triggered by a background network request from a page or extension, it is displayed over the currently loaded foreground page. Although the prompt contains the real domain making the request, this can result in user confusion about the…

  • CVE-2018-5113HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

  • CVE-2018-5112HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should…

  • CVE-2018-5101HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A use-after-free vulnerability can occur when manipulating floating "first-letter" style elements, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.

  • CVE-2018-5100HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.05

    A use-after-free vulnerability can occur when arguments passed to the "IsPotentiallyScrollable" function are freed while still in use by scripts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 58.

  • CVE-2017-7843HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.03

    When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB should not be available in Private Browsing mode and this stored data will persist across multiple private browsing mode sessions…

  • CVE-2017-7806HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.

  • CVE-2017-7805HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.03

    During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This…

  • CVE-2017-7804HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.01

    The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memory protections in this…

  • CVE-2017-7803HigJun 11, 2018
    risk 0.49cvss 7.5epss 0.02

    When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

Page 60 of 168