Search CVE reports


Toggle filters

1371 – 1380 of 3038 results


CVE-2017-7825

Medium priority
Not affected

Several fonts on OS X display some Tibetan and Arabic characters as whitespace. When used in the addressbar as part of an IDN this can be used for domain name spoofing attacks. Note: This attack only affects OS X operating...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected
thunderbird Not affected
Show less packages

CVE-2017-7817

Medium priority
Not affected

A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. This allows an attacker to spoof which page is actually loaded and in use. Note:...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Not affected
Show less packages

CVE-2017-7804

Medium priority
Not affected

The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
thunderbird
Show less packages

CVE-2017-7796

Medium priority
Not affected

On Windows systems, the logger run by the Windows updater deletes the file "update.log" before it runs in order to write a new log of that name. The path to this file is supplied at the command line to the updater and could be...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
Show less packages

CVE-2017-7790

Medium priority
Not affected

On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, stack memory data can be copied until a null is found. This can potentially contain private data from the local...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
Show less packages

CVE-2017-7782

Medium priority
Not affected

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems...

2 affected packages

firefox, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
thunderbird
Show less packages

CVE-2017-7770

Medium priority
Not affected

A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
Show less packages

CVE-2017-7768

Medium priority
Not affected

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater....

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
Show less packages

CVE-2017-7767

Medium priority
Not affected

The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
Show less packages

CVE-2017-7766

Medium priority
Not affected

An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance...

1 affected package

firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox
Show less packages