|
211801
|
- |
|
mozilla opensuse fedoraproject
|
firefox leap opensuse fedora
|
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7217
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211802
|
- |
|
fedoraproject mozilla opensuse
|
fedora firefox leap opensuse
|
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly hav…
|
CWE-20
Improper Input Validation
|
CVE-2015-7216
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211803
|
- |
|
fedoraproject opensuse mozilla
|
fedora leap opensuse firefox
|
The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the f…
|
CWE-200
Information Exposure
|
CVE-2015-7215
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211804
|
- |
|
opensuse mozilla fedoraproject
|
leap opensuse firefox fedora
|
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
|
CWE-200
Information Exposure
|
CVE-2015-7214
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211805
|
- |
|
opensuse fedoraproject mozilla
|
leap opensuse fedora firefox
|
Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote…
|
CWE-189
Numeric Errors
|
CVE-2015-7213
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211806
|
- |
|
fedoraproject opensuse mozilla
|
fedora leap opensuse firefox
|
Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary …
|
CWE-189
Numeric Errors
|
CVE-2015-7212
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211807
|
- |
|
mozilla fedoraproject opensuse
|
firefox fedora leap opensuse
|
Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-7211
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211808
|
- |
|
mozilla opensuse fedoraproject
|
firefox leap opensuse fedora
|
Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering attempted use of a data channel that has b…
|
NVD-CWE-Other
|
CVE-2015-7210
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211809
|
- |
|
mozilla fedoraproject opensuse
|
firefox fedora leap opensuse
|
Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.
|
CWE-200
Information Exposure
|
CVE-2015-7208
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211810
|
- |
|
mozilla opensuse fedoraproject
|
firefox leap opensuse fedora
|
Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive inform…
|
CWE-200
Information Exposure
|
CVE-2015-7207
|
2024-11-21 11:36 |
2015-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|