Vulnérabilités
Vulnérabilités des apps suivies
845 entrées
Tri chronologique : du plus récent au plus ancien. Pour prioriser, utilise les filtres KEV / sévérité ci-dessus.
| CVE |
|---|
|
CVE-2017-7786
CRITICAL 9.8
Réseau 1 apps
A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulne… |
|
CVE-2017-7785
CRITICAL 9.8
Réseau 1 apps
A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable… |
|
CVE-2017-7784
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potent… |
|
CVE-2017-7779
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs were reported in Firefox 54, Firefox ESR 52.2, and Thunderbird 52.2. Some of these bugs showed evidence of memory corruption and we presume … |
|
CVE-2017-7778
CRITICAL 9.8
Réseau 1 apps
A number of security vulnerabilities in the Graphite 2 library including out-of-bounds reads, buffer overflow reads and writes, and the use of uninitialized me… |
|
CVE-2017-7758
CRITICAL 9.1
Réseau 1 apps
An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerabilit… |
|
CVE-2017-7757
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a pote… |
|
CVE-2017-7756
CRITICAL 9.8
Réseau 1 apps
A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable… |
|
CVE-2017-7753
CRITICAL 9.1
Réseau 1 apps
An out-of-bounds read occurs when applying style rules to pseudo-elements, such as ::first-line, using cached style data. This vulnerability affects Thunderbir… |
|
CVE-2017-7751
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability with content viewer listeners that results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox … |
|
CVE-2017-7750
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability during video control operations when a "<track>" element holds a reference to an older window if that window has been replaced i… |
|
CVE-2017-7749
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability when using an incorrect URL during the reloading of a docshell. This results in a potentially exploitable crash. This vulnerabil… |
|
CVE-2017-5472
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability with the frameloader during tree reconstruction while regenerating CSS layout when attempting to use a node in the tree that no … |
|
CVE-2017-5470
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs were reported in Firefox 53 and Firefox ESR 52.1. Some of these bugs showed evidence of memory corruption and we presume that with enough ef… |
|
CVE-2017-5469
CRITICAL 9.8
Réseau 1 apps
Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.… |
|
CVE-2017-5465
CRITICAL 9.1
Réseau 1 apps
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied i… |
|
CVE-2017-5464
CRITICAL 9.8
Réseau 1 apps
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruptio… |
|
CVE-2017-5460
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potential… |
|
CVE-2017-5459
CRITICAL 9.8
Réseau 1 apps
A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR… |
|
CVE-2017-5447
CRITICAL 9.1
Réseau 1 apps
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to … |
|
CVE-2017-5446
CRITICAL 9.8
Réseau 1 apps
An out-of-bounds read when an HTTP/2 connection to a servers sends "DATA" frames with incorrect data content. This leads to a potentially exploitable crash. Th… |
|
CVE-2017-5443
CRITICAL 9.8
Réseau 1 apps
An out-of-bounds write vulnerability while decoding improperly formed BinHex format archives. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9… |
|
CVE-2017-5442
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability during changes in style when manipulating DOM elements. This results in a potentially exploitable crash. This vulnerability affe… |
|
CVE-2017-5441
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability when holding a selection during scroll events. This results in a potentially exploitable crash. This vulnerability affects Thund… |
|
CVE-2017-5440
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability during XSLT processing due to a failure to propagate error conditions during matching while evaluating context, leading to objec… |
|
CVE-2017-5439
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability during XSLT processing due to poor handling of template parameters. This results in a potentially exploitable crash. This vulner… |
|
CVE-2017-5438
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability during XSLT processing due to the result handler being held by a freed handler during handling. This results in a potentially ex… |
|
CVE-2017-5435
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability occurs during transaction processing in the editor during design mode interactions. This results in a potentially exploitable cr… |
|
CVE-2017-5434
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability occurs when redirecting focus handling which results in a potentially exploitable crash. This vulnerability affects Thunderbird … |
|
CVE-2017-5433
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability in SMIL animation functions occurs when pointers to animation elements in an array are dropped from the animation controller whi… |
|
CVE-2017-5432
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird … |
|
CVE-2017-5430
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that… |
|
CVE-2017-5429
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption a… |
|
CVE-2017-5413
CRITICAL 9.8
Réseau 1 apps
A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52. |
|
CVE-2017-5410
CRITICAL 9.8
Réseau 1 apps
Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for me… |
|
CVE-2017-5404
CRITICAL 9.8
Réseau 1 apps
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results i… |
|
CVE-2017-5403
CRITICAL 9.8
Réseau 1 apps
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, res… |
|
CVE-2017-5402
CRITICAL 9.8
Réseau 1 apps
A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This result… |
|
CVE-2017-5401
CRITICAL 9.8
Réseau 1 apps
A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vu… |
|
CVE-2017-5400
CRITICAL 9.8
Réseau 1 apps
JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vuln… |
|
CVE-2017-5399
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs were reported in Firefox 51. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of the… |
|
CVE-2017-5398
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs were reported in Thunderbird 45.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some … |
|
CVE-2017-5396
CRITICAL 9.8
Réseau 1 apps
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. Th… |
|
CVE-2017-5390
CRITICAL 9.8
Réseau 1 apps
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for … |
|
CVE-2017-5380
CRITICAL 9.8
Réseau 1 apps
A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and… |
|
CVE-2017-5376
CRITICAL 9.8
Réseau 1 apps
Use-after-free while manipulating XSL in XSLT documents. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. |
|
CVE-2017-5375
CRITICAL 9.8
Réseau 1 apps
JIT code allocation can allow for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Thunderbird <… |
|
CVE-2017-5373
CRITICAL 9.8
Réseau 1 apps
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough … |
|
CVE-2016-9899
CRITICAL 9.8
Réseau 1 apps
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 5… |
|
CVE-2016-9898
CRITICAL 9.8
Réseau 1 apps
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR … |