NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 27874 | CVE-2015-7187 | The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27875 | CVE-2015-7188 | Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string. | 2 | 7.5 | High | 2017-01-19 | 2016-12-07 | View | |
| 27876 | CVE-2015-7189 | Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code. | 2 | 6.8 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27877 | CVE-2015-7190 | The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application. | 2 | 5 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 27878 | CVE-2015-7191 | Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)." | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 14898 of 17672, showing 5 records out of 88360 total, starting on record 74486, ending on 74490