Search CVE reports


Toggle filters

1521 – 1530 of 3038 results


CVE-2017-7806

Medium priority

Some fixes available 17 of 20

A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.

2 affected packages

firefox, mozjs38

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
Show less packages

CVE-2017-7803

Medium priority

Some fixes available 14 of 16

When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3,...

3 affected packages

firefox, mozjs38, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
mozjs38 Not affected
thunderbird Fixed
Show less packages

CVE-2017-7802

Medium priority

Some fixes available 14 of 16

A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when...

3 affected packages

firefox, mozjs38, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
mozjs38 Not affected
thunderbird Fixed
Show less packages

CVE-2017-7801

Medium priority

Some fixes available 14 of 16

A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This...

3 affected packages

firefox, mozjs38, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
mozjs38 Not affected
thunderbird Fixed
Show less packages

CVE-2017-7800

Medium priority

Some fixes available 14 of 16

A use-after-free vulnerability can occur in WebSockets when the object holding the connection is freed before the disconnection operation is finished. This results in an exploitable crash. This vulnerability affects Thunderbird <...

3 affected packages

firefox, thunderbird, mozjs38

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
thunderbird Fixed
mozjs38 Not affected
Show less packages

CVE-2017-7799

Medium priority

Some fixes available 17 of 20

JavaScript in the "about:webrtc" page is not sanitized properly being assigned to "innerHTML". Data on this page is supplied by WebRTC usage and is not under third-party control, making this difficult to exploit, but...

2 affected packages

mozjs38, firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 Not in release Not in release Not in release Ignored
firefox Fixed Fixed Fixed Fixed
Show less packages

CVE-2017-7798

Medium priority

Some fixes available 17 of 20

The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page with the...

2 affected packages

mozjs38, firefox

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
mozjs38 Not in release Not in release Not in release Ignored
firefox Fixed Fixed Fixed Fixed
Show less packages

CVE-2017-7797

Medium priority

Some fixes available 17 of 20

Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.

2 affected packages

firefox, mozjs38

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
Show less packages

CVE-2017-7794

Medium priority

Some fixes available 17 of 20

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This...

2 affected packages

firefox, mozjs38

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed Fixed Fixed Fixed
mozjs38 Not in release Not in release Not in release Ignored
Show less packages

CVE-2017-7792

Medium priority

Some fixes available 14 of 16

A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability...

3 affected packages

firefox, mozjs38, thunderbird

Package 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
firefox Fixed
mozjs38 Not affected
thunderbird Fixed
Show less packages