|
1161
|
7.5
5.0
|
HIGH
Network
|
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This all…
|
CWE-200
Information Exposure
|
CVE-2017-5454
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1162
|
4.3
4.3
|
MEDIUM
Network
|
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to b…
|
CWE-20
Improper Input Validation
|
CVE-2017-5451
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1163
|
8.6
7.5
|
HIGH
Network
|
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechan…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-5448
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1164
|
9.1
6.4
|
CRITICAL
Network
|
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This…
|
CWE-416
Use After Free
|
CVE-2017-5447
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1165
|
9.8
7.5
|
CRITICAL
Network
|
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. This vulnerability affects Thunderbird < 5…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-5446
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1166
|
7.5
5.0
|
HIGH
Network
|
A vulnerability while parsing "application/http-index-format" format content where uninitialized values are used to create an array. This could allow the reading of uninitialized memory into the arra…
|
CWE-129
Improper Validation of Array Index
|
CVE-2017-5445
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1167
|
7.5
5.0
|
HIGH
Network
|
A buffer overflow vulnerability while parsing "application/http-index-format" format content when the header contains improperly formatted data. This allows for an out-of-bounds read of data from mem…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-5444
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1168
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objects being used when they no longer exist.…
|
CWE-416
Use After Free
|
CVE-2017-5440
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1169
|
9.8
7.5
|
CRITICAL
Network
|
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially exploitable crash. This vulnerability affe…
|
CWE-416
Use After Free
|
CVE-2017-5438
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1170
|
8.8
6.8
|
HIGH
Network
|
An out-of-bounds write in the Graphite 2 library triggered with a maliciously crafted Graphite font. This results in a potentially exploitable crash. This issue was fixed in the Graphite 2 library as…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-5436
|
cpe:2.3:o:redhat:enterprise_linux:7.0:* cpe:2.3:o:redhat:enterprise_linux:6.0:*
|
|
|
|
|
2024-11-21 12:27
2018-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|