NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 25942 | CVE-2015-4519 | Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect"s target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-21 | View | |
| 25941 | CVE-2015-4518 | The Reader View implementation in Mozilla Firefox before 42.0 has an improper whitelist, which makes it easier for remote attackers to bypass the Content Security Policy (CSP) protection mechanism and conduct cross-site scripting (XSS) attacks via vectors involving SVG animations and the about:reader URL. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View | |
| 25940 | CVE-2015-4517 | NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. | 2 | 7.5 | High | 2017-01-19 | 2016-12-21 | View | |
| 25939 | CVE-2015-4516 | Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs. | 2 | 9.3 | High | 2017-01-19 | 2016-12-21 | View | |
| 25938 | CVE-2015-4515 | Mozilla Firefox before 42.0, when NTLM v1 is enabled for HTTP authentication, allows remote attackers to obtain sensitive hostname information by constructing a crafted web site that sends an NTLM request and reads the Workstation field of an NTLM type 3 message. | 2 | 4.3 | Medium | 2017-01-19 | 2016-12-07 | View |
Page 3170 of 17672, showing 5 records out of 88360 total, starting on record 15846, ending on 15850