NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25938 | CVE-2015-4515 | Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 25939 | CVE-2015-4516 | Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs. | 2 | 9.3 | High | 2017-01-19 | 2016-12-21 | View | |
| 25940 | CVE-2015-4517 | NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View | |
| 25941 | CVE-2015-4518 | The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 25942 | CVE-2015-4519 | Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect"s target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View |
Page 14503 of 17672, showing 5 records out of 88360 total, starting on record 72511, ending on 72515