• Close
  • Vulnerability Database

    The Rapid7 Vulnerability Database is a list of 70,000 vulnerabilities for security analyst and researchers to identify and address known security issues through vulnerability management solutions. Each vulnerability has links to relevant groups like Mitre and other CVE Numbering Authorities as well as additional technical documentation. These vulnerabilities are utilized by our vulnerability management tool Nexpose and provided here for additional visibility.

    Displaying vulnerability details 41 - 50 of 76901 in total

    Debian: DSA-3674 (CVE-2016-5272): firefox-esr -- security update Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    The nsImageGeometryMixin class in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arbitrary code via a crafted web site.

    Ubuntu: USN-3076-1 (CVE-2016-2827): Firefox vulnerabilities Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.

    Ubuntu: USN-3076-1 (CVE-2016-5271): Firefox vulnerabilities Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.

    Cent OS: CVE-2016-5274: CESA-2016:1912 (firefox) Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between restyling and the Web Animations model implementation.

    Ubuntu: USN-3076-1 (CVE-2016-5282): Firefox vulnerabilities Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

    Cent OS: CVE-2016-5278: CESA-2016:1912 (firefox) Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.

    Debian: DSA-3674 (CVE-2016-5281): firefox-esr -- security update Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.

    Ubuntu: USN-3076-1 (CVE-2016-5283): Firefox vulnerabilities Vulnerability

    • Severity: 7
    • Published: September 21, 2016

    Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

    Debian: DSA-3674 (CVE-2016-5274): firefox-esr -- security update Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between restyling and the Web Animations model implementation.

    Debian: DSA-3674 (CVE-2016-5276): firefox-esr -- security update Vulnerability

    • Severity: 4
    • Published: September 21, 2016

    Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0 and Firefox ESR 45.x before 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via an aria-owns attribute.