NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20598 | CVE-2016-5275 | Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering. | 2 | 6.8 | Medium | 2017-01-19 | 2016-11-28 | View | |
20599 | CVE-2016-5276 | Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute. | 2 | 7.5 | High | 2017-01-19 | 2017-01-17 | View | |
20600 | CVE-2016-5277 | Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation. | 2 | 7.5 | High | 2017-01-19 | 2017-01-17 | View | |
20601 | CVE-2016-5278 | Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image. | 2 | 6.8 | Medium | 2017-01-19 | 2017-01-17 | View | |
20602 | CVE-2016-5279 | Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16087 of 17672, showing 5 records out of 88360 total, starting on record 80431, ending on 80435