Latest CVE Feed
-
10.0
HIGHCVE-2016-1962
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connectio... Read more
- EPSS Score: %4.44
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1961
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root eleme... Read more
- EPSS Score: %1.25
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mish... Read more
- EPSS Score: %87.70
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1959
The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.... Read more
Affected Products : firefox- EPSS Score: %0.75
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1958
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.... Read more
- EPSS Score: %0.54
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1957
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.... Read more
Affected Products : firefox firefox_esr thunderbird leap linux opensuse suse_package_hub_for_suse_linux_enterprise- EPSS Score: %0.67
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
7.1
HIGHCVE-2016-1956
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.... Read more
- EPSS Score: %0.90
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1955
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.... Read more
- EPSS Score: %0.37
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1954
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote... Read more
Affected Products : firefox firefox_esr thunderbird leap linux opensuse suse_package_hub_for_suse_linux_enterprise- EPSS Score: %5.06
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1953
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/ar... Read more
Affected Products : firefox firefox_esr thunderbird leap opensuse suse_package_hub_for_suse_linux_enterprise- EPSS Score: %1.23
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1952
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via... Read more
Affected Products : firefox firefox_esr thunderbird leap linux opensuse suse_package_hub_for_suse_linux_enterprise- EPSS Score: %0.61
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1950
Heap-based buffer overflow in Mozilla Network Security Services (NSS) before 3.19.2.3 and 3.20.x and 3.21.x before 3.21.1, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code via craft... Read more
Affected Products : firefox firefox_esr iplanet_web_server mac_os_x linux glassfish_server opensuse iphone_os tvos watchos +3 more products- EPSS Score: %1.75
- Published: Mar. 13, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-1621
libvpx in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.0 before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, related to libwebm/mkvparser... Read more
Affected Products : android- EPSS Score: %8.45
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
6.6
MEDIUMCVE-2016-0832
Setup Wizard in Android 5.1.x before LMY49H and 6.x before 2016-03-01 allows physically proximate attackers to bypass the Factory Reset Protection protection mechanism and delete data via unspecified vectors, aka internal bug 25955042.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-0831
The getDeviceIdForPhone function in internal/telephony/PhoneSubInfoController.java in Telephony in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not check for the READ_PHONE_STATE permission, which allows attackers to obtain sensitive inf... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-0830
btif_config.c in Bluetooth in Android 6.x before 2016-03-01 allows remote attackers to cause a denial of service (memory corruption and persistent daemon crash) by triggering a large number of configuration entries, and consequently exceeding the maximum ... Read more
Affected Products : android- EPSS Score: %0.24
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-0829
The BnGraphicBufferProducer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not initialize a certain output data structure, which allows attack... Read more
Affected Products : android- EPSS Score: %0.20
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-0828
The BnGraphicBufferConsumer::onTransact function in libs/gui/IGraphicBufferConsumer.cpp in mediaserver in Android 5.x before 5.1.1 LMY49H and 6.x before 2016-03-01 does not initialize a certain slot variable, which allows attackers to obtain sensitive inf... Read more
Affected Products : android- EPSS Score: %0.20
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0827
Multiple integer overflows in libeffects in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allow attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSyst... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2016-0826
libcameraservice in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 does not require use of the ICameraService::dump method for a camera service dump, which allows attackers to gain privileges via a crafted appl... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Mar. 12, 2016
- Modified: Apr. 12, 2025