• Close
  • Vulnerability Database

    The Rapid7 Vulnerability Database is a list of 70,000 vulnerabilities for security analyst and researchers to identify and address known security issues through vulnerability management solutions. Each vulnerability has links to relevant groups like Mitre and other CVE Numbering Authorities as well as additional technical documentation. These vulnerabilities are utilized by our vulnerability management tool Nexpose and provided here for additional visibility.

    Displaying vulnerability details 11 - 20 of 76901 in total

    Ubuntu: USN-3087-2: OpenSSL regression Vulnerability

    • Severity: 4
    • Published: September 22, 2016

    USN-3087-1 fixed vulnerabilities in OpenSSL. The fix forCVE-2016-2182was incomplete and caused a regression when parsing certificates. This update fixes the problem.

    We apologize for the inconvenience.

    Original advisory details:

    Shi Lei discovered that OpenSSL incorrectly handled the OCSP Status Request e...

    Ubuntu: USN-3076-1 (CVE-2016-5273): Firefox vulnerabilities Vulnerability

    • Severity: 7
    • Published: September 21, 2016

    The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.

    Ubuntu: USN-3076-1 (CVE-2016-5276): Firefox vulnerabilities Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute.

    Debian: DSA-3674 (CVE-2016-5270): firefox-esr -- security update Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to cause a denial of service (boolean out-of-bounds write) or possibly have unspecified other impact via Unicode characters that are mishandled during text conve...

    Ubuntu: USN-3076-1 (CVE-2016-5283): Firefox vulnerabilities Vulnerability

    • Severity: 7
    • Published: September 21, 2016

    Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

    Oracle Linux: CVE-2016-5281: ELSA-2016-1912 - firefox security update Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.

    Ubuntu: USN-3076-1 (CVE-2016-5284): Firefox vulnerabilities Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.

    Ubuntu: USN-3076-1 (CVE-2016-5279): Firefox vulnerabilities Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.

    Ubuntu: USN-3076-1 (CVE-2016-5275): Firefox vulnerabilities Vulnerability

    • Severity: 7
    • Published: September 21, 2016

    Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.

    Cent OS: CVE-2016-5270: CESA-2016:1912 (firefox) Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Heap-based buffer overflow in the nsCaseTransformTextRunFactory::TransformString function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to cause a denial of service (boolean out-of-bounds write) or possibly have unspecified other impact via Unicode characters that are mishandled during text conve...