Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, HLOS can overwite secure memory or read contents of the keystore.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, there was an issue related to RPMB processing.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In all Android releases from CAF using the Linux kernel, stack protection was not enabled for secure applications.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In TrustZone in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.
Published Jun 6, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and information disclosure.
Published Jun 29, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Sterling Order Management 9.2 through 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 121314.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
Published Jun 6, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier. An attacker could exploit this vulnerability to gain access to another user's session. IBM X-Force ID: 120253.
Published Jun 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
game-music-emu before 0.6.1 mishandles unspecified integer values.
Published Jun 6, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120209.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Maximo Asset Management 7.5 and 7.6 could allow a remote authenticated attacker to execute arbitrary commands on the system as administrator. IBM X-Force ID: 120276.
Published Jun 13, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
HTML tags received from the Pocket server will be processed without sanitization and any JavaScript code executed will be run in the "about:pocket-saved" (unprivileged) page, giving it access to Pocket's messaging API through HTML injection. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
External resources that should be blocked when loaded by SVG images can bypass security restrictions through the use of "data:" URLs. This could allow for cross-domain data leakage. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user with special privileges to view files that they should not have access to. IBM X-Force ID: 120275.
Published Jun 22, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Sterling B2B Integrator Standard Edition 5.2 could allow an authenticated user to obtain sensitive information such as account lists due to improper access control. IBM X-Force ID: 120274.
Published Jun 22, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM QRadar 7.2 and 7.3 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 120208.
Published Jun 27, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Event handlers on "marquee" elements were executed despite a strict Content Security Policy (CSP) that disallowed inline JavaScript. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Use-after-free resulting in potentially exploitable crash when manipulating DOM subtrees in the Editor. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory safety bugs were reported in Thunderbird 45.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buffer, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.1.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory corruption resulting in a potentially exploitable crash during WebGL functions using a vector constructor with a varying array within libGLES. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM RELM 4.0, 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Published Jun 22, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An XSS vulnerability allows remote attackers to execute arbitrary client side script on vulnerable installations of Sophos Cyberoam firewall devices with firmware through 10.6.4. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of a request to the "LiveConnectionDetail.jsp" application. GET parameters "applicationname" and "username" are improperly sanitized allowing an attacker to inject arbitrary JavaScript into the page. This can be abused by an attacker to perform a cross-site scripting attack on the user. A vulnerable URI is /corporate/webpages/trafficdiscovery/LiveConnectionDetail.jsp.
Published Jun 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM WebSphere Application Server using malformed SOAP requests could allow a remote attacker to obtain sensitive information.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM QRadar 7.2 and 7.3 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 119783.
Published Jun 27, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Rhapsody DM 4.0, 5.0, and 6.0 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources. IBM Reference #: 1999960.
Published Jun 8, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
IBM Predictive Solutions Foundation (formerly PMQ) could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a file from the local system, which could allow the attacker to obtain sensitive information. IBM X-Force ID: 119618.
Published Jun 7, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from a Reflected Cross-Site Scripting vulnerability. Applications Manager is prone to a Cross-Site Scripting vulnerability in parameter LIMIT, in URL path /DiagAlertAction.do?REQTYPE=AJAX&LIMIT=1233. The URL is also available without authentication.
Published Jun 5, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
ManageEngine Applications Manager versions 12 and 13 before build 13200 suffer from remote SQL injection vulnerabilities. An unauthenticated attacker is able to access the URL /servlet/MenuHandlerServlet, which is vulnerable to SQL injection. The attacker could extract users' password hashes, which are MD5 hashes without salt, and, depending on the database type and its configuration, could also execute operating system commands using SQL queries.
Published Jun 5, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dual Cam v139, IPM3 Single Cam v132, P520, P574, SensorX13 QC flow line, SensorX23 QC Master, SensorX23 QC Slave, Speed Batcher, T374, T377, V36, V36B, and V36C; M3210 terminal associated with the same systems as the M3000 terminal identified above; M3000 desktop software associated with the same systems as the M3000 terminal identified above; MAC4 controller associated with the same systems as the M3000 terminal identified above; SensorX23 X-ray machine; SensorX25 X-ray machine; and MWS2 weighing system. The end user does not have the ability to change system passwords.
Published Jun 30, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50. This vulnerability affects Firefox < 50.0.1.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
Published Jun 11, 2018 · Updated Aug 6, 2024