
CVE-2016-5281 – Mozilla: use-after-free in DOMSVGLength (MFSA 2016-85, MFSA 2016-86)
https://notcve.org/view.php?id=CVE-2016-5281
21 Sep 2016 — Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document. Vulnerabilidad de uso de memoria previamente liberada en la claseDOMSVGLength en Mozilla Firefox en versiones anteriores a la 49.0, Firefox ESR en versiones 45.x anteriores a la 45.4 y Thunderbird en versiones anteriores a la 45.4 permite que... • http://rhn.redhat.com/errata/RHSA-2016-1912.html • CWE-416: Use After Free •

CVE-2016-5274 – Mozilla: use-after-free in nsFrameManager::CaptureFrameState (MFSA 2016-85, MFSA 2016-86)
https://notcve.org/view.php?id=CVE-2016-5274
21 Sep 2016 — Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between restyling and the Web Animations model implementation. Vulnerabilidad de uso de memoria previamente liberada en la función nsFrameManager::CaptureFrameState en Mozilla Firefox en versiones 45.x anteriores a la 49.0, Firefox ESR en versiones anteriores a l... • http://rhn.redhat.com/errata/RHSA-2016-1912.html • CWE-416: Use After Free •

CVE-2016-5253 – Gentoo Linux Security Advisory 201701-15
https://notcve.org/view.php?id=CVE-2016-5253
05 Aug 2016 — The Updater in Mozilla Firefox before 48.0 on Windows allows local users to write to arbitrary files via vectors involving the callback application-path parameter and a hard link. El Updater en Mozilla Firefox en versiones anteriores a 48.0 en Windows permite a usuarios locales escribir a archivos arbitrarios a través de vectores que involucran el parámetro de aplicación de ruta de llamada de retorno y un enlace duro. Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird th... • http://www.mozilla.org/security/announce/2016/mfsa2016-69.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-5267 – Gentoo Linux Security Advisory 201701-15
https://notcve.org/view.php?id=CVE-2016-5267
05 Aug 2016 — Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set. Mozilla Firefox en versiones anteriores a 48.0 en Android permite a atacantes remotos suplantar la barra de direcciones a través de caracteres de izquierda a derecha en conjunción con un set de caracteres derecha a izquierda. Multiple vulnerabilities have been found in Mozilla Firefox, SeaMonkey, and Thunderbird the worst of which could lead ... • http://www.mozilla.org/security/announce/2016/mfsa2016-82.html • CWE-20: Improper Input Validation •

CVE-2016-2839 – Gentoo Linux Security Advisory 201701-15
https://notcve.org/view.php?id=CVE-2016-2839
05 Aug 2016 — Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 on Linux make cairo _cairo_surface_get_extents calls that do not properly interact with libav header allocation in FFmpeg 0.10, which allows remote attackers to cause a denial of service (application crash) via a crafted video. Mozilla Firefox en versiones anteriores a 48.0 y Firefox ESR 45.x en versiones anteriores a 45.3 en Linux hace llamadas cairo _cairo_surface_get_extents que no interactúan adecuadamente con asignación de cabecera libav en F... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html • CWE-20: Improper Input Validation •

CVE-2016-5268 – Gentoo Linux Security Advisory 201701-15
https://notcve.org/view.php?id=CVE-2016-5268
05 Aug 2016 — Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring. Mozilla Firefox en versiones anteriores a 48.0 no fija adecuadamente los indicadores LINKABLE y URI_SAFE_FOR_UNTRUSTED_CONTENT de about: URLs que se usan para páginas de error, lo que facilita a atac... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html • CWE-254: 7PK - Security Features •

CVE-2016-5250 – Mozilla: Resource Timing API is storing resources sent by the previous page (MFSA 2016-84, MFSA 2016-86)
https://notcve.org/view.php?id=CVE-2016-5250
05 Aug 2016 — Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls. Mozilla Firefox en versiones anteriores a la 48.0, Firefox ESR en versiones anteriores a la 45.4 y Thunderbird en versiones anteriores a la 45.4 permiten que los atacantes remotos obtengan información sensible sombre la página previamente recuperada mediante llamadas a la API Resource Timing. Catalin Dumitru discovere... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-5266 – Gentoo Linux Security Advisory 201701-15
https://notcve.org/view.php?id=CVE-2016-5266
05 Aug 2016 — Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site. Mozilla Firefox en versiones anteriores a 48.0 no restringe adecuadamente acciones arrastrar y soltar (también conocido como dataTransfer) para file: URIs, lo que permite a atacantes remotos asistidos por usuario acceder a archivos locales a través de un sitio web manipulado. Gustavo Grieco discovered an out-... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2016-2835 – Gentoo Linux Security Advisory 201701-15
https://notcve.org/view.php?id=CVE-2016-2835
05 Aug 2016 — Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Multiples vulnerabilidades no especificadas en el motor del navegador en Mozilla Firefox en versiones anteriores a 48.0 permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria y caída de aplicación) o posiblemente ejecutar código arbitrario ... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html •

CVE-2016-5255 – Gentoo Linux Security Advisory 201701-15
https://notcve.org/view.php?id=CVE-2016-5255
05 Aug 2016 — Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection. Vulnerabilidad de uso después de liberación de memoria en la función js::PreliminaryObjectArray::sweep en Mozilla Firefox en versiones anteriores a 48.0 permite a atacantes remotos ejecutar código arbitrario a través de JavaScript manipulado que es manejado incorrectamen... • http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00004.html • CWE-416: Use After Free •