Latest CVE Feed
-
5.9
MEDIUMCVE-2016-9076
An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulnerability affects Firefox < 50.... Read more
Affected Products : firefox- EPSS Score: %0.37
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9075
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This... Read more
Affected Products : firefox- EPSS Score: %3.30
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2016-9074
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.... Read more
- EPSS Score: %1.29
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-9073
WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.... Read more
Affected Products : firefox- EPSS Score: %0.85
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-9072
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected. This vulnerabil... Read more
- EPSS Score: %0.85
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2016-9071
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.... Read more
Affected Products : firefox- EPSS Score: %0.47
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
8.0
HIGHCVE-2016-9070
A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulnerability affects Firefox < 50.... Read more
Affected Products : firefox- EPSS Score: %0.86
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2016-9069
A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.... Read more
Affected Products : firefox- EPSS Score: %0.30
- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-9068
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.... Read more
Affected Products : firefox- EPSS Score: %2.58
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2016-9067
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.... Read more
Affected Products : firefox- EPSS Score: %2.04
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-9066
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.... Read more
- EPSS Score: %20.61
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-9065
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and o... Read more
- EPSS Score: %0.37
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2016-9064
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinn... Read more
- EPSS Score: %0.27
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2016-9063
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.... Read more
- EPSS Score: %1.90
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
3.3
LOWCVE-2016-9062
Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the Firefox profile after the mode is exited. Note: This issue only affects Firefox for Android. Other versions and operat... Read more
- EPSS Score: %0.08
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2016-9061
A previously installed malicious Android application which defines a specific signature-level permissions used by Firefox can access API keys meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems a... Read more
- EPSS Score: %0.91
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.4
HIGHCVE-2016-9048
Multiple exploitable SQL Injection vulnerabilities exists in ProcessMaker Enterprise Core 3.0.1.7-community. Specially crafted web requests can cause SQL injections. An attacker can send a web request with parameters containing SQL injection attacks to tr... Read more
Affected Products : processmaker- EPSS Score: %0.26
- Published: Sep. 10, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-9045
A code execution vulnerability exists in ProcessMaker Enterprise Core 3.0.1.7-community. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to tri... Read more
Affected Products : processmaker- EPSS Score: %0.24
- Published: Sep. 17, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2016-9044
An exploitable command execution vulnerability exists in Information Builders WebFOCUS Business Intelligence Portal 8.1 . A specially crafted web parameter can cause a command injection. An authenticated attacker can send a crafted web request to trigger ... Read more
Affected Products : webfocus- EPSS Score: %0.87
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2016-9043
An out of bound write vulnerability exists in the EMF parsing functionality of CorelDRAW X8 (CdrGfx - Corel Graphics Engine (64-Bit) - 18.1.0.661). A specially crafted EMF file can cause a vulnerability resulting in potential code execution. An attacker c... Read more
Affected Products : coreldraw- EPSS Score: %0.96
- Published: Apr. 24, 2018
- Modified: Nov. 21, 2024