NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20583 | CVE-2016-5259 | Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
20584 | CVE-2016-5260 | Mozilla Firefox before 48.0 mishandles changes from "INPUT type="password"" to "INPUT type="text"" within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20585 | CVE-2016-5261 | Integer overflow in the WebSocketChannel class in the WebSockets subsystem in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets that trigger incorrect buffer-resize operations during buffering. | 2 | 7.5 | High | 2017-01-19 | 2017-01-17 | View | |
20586 | CVE-2016-5262 | Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted web site. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20587 | CVE-2016-5263 | The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion." | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16084 of 17672, showing 5 records out of 88360 total, starting on record 80416, ending on 80420