|
1151
|
7.5
5.0
|
HIGH
Network
|
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. Thi…
|
CWE-200
Information Exposure
|
CVE-2017-7787
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1152
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerabil…
|
CWE-416
Use After Free
|
CVE-2017-7784
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1153
|
8.8
6.8
|
HIGH
Network
|
A use-after-free vulnerability during specific user interactions with the input method editor (IME) in some languages due to how events are handled. This results in a potentially exploitable crash bu…
|
CWE-416
Use After Free
|
CVE-2017-7752
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1154
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older window if that window has been replaced in the DOM. This results in a potentially…
|
CWE-416
Use After Free
|
CVE-2017-7750
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:32
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1155
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no longer exists. This results in a potenti…
|
CWE-416
Use After Free
|
CVE-2017-5472
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1156
|
9.8
7.5
|
CRITICAL
Network
|
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploit…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5470
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1157
|
6.1
4.3
|
MEDIUM
Network
|
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set in…
|
CWE-79
Cross-site Scripting
|
CVE-2017-5466
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1158
|
9.1
6.4
|
CRITICAL
Network
|
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could the…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5465
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1159
|
9.8
7.5
|
CRITICAL
Network
|
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. T…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5464
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1160
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability…
|
CWE-416
Use After Free
|
CVE-2017-5460
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|