
CVE-2016-2825 – Ubuntu Security Notice USN-2993-1
https://notcve.org/view.php?id=CVE-2016-2825
09 Jun 2016 — Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL. Mozilla Firefox en versiones anteriores a 47.0 permite a atacantes remotos eludir la Same Origin Policy y modificar la propiedad location.host a través de un dato no válido: URL. Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel, Sylvestre Ledru, Julian Seward, Olli Pettay, Karl Tomlinson, Christoph Diehl, Julian Hector, Jan de Mooij, Ma... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html • CWE-284: Improper Access Control •

CVE-2016-2832 – Ubuntu Security Notice USN-2993-1
https://notcve.org/view.php?id=CVE-2016-2832
09 Jun 2016 — Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes. Mozilla Firefox en versiones anteriores a 47.0 permite a atacantes remotos descubrir la lista de plugins deshabilitadas a través de un ataque de huellas dactilares involucrando pseudo clases Cascading Style Sheets (CSS). Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel, Sylvestre Ledru, Julian Seward, Olli Pet... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2016-2822 – Mozilla: Addressbar spoofing though the SELECT element (MFSA 2016-52)
https://notcve.org/view.php?id=CVE-2016-2822
09 Jun 2016 — Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to spoof the address bar via a SELECT element with a persistent menu. Mozilla Firefox en versiones anteriores a 47.0 y Firefox ESR 45.x en versiones anteriores a 45.2 permite a atacantes remotos suplantar la barra de dirección a través de un elemento SELECT con un menú persistente. Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel, Sylvestre Ledru, Julian Seward, Olli Pettay, Karl Tomlinson, Christoph... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html • CWE-284: Improper Access Control •

CVE-2016-2831 – Mozilla: Entering fullscreen and persistent pointerlock without user permission (MFSA 2016-58)
https://notcve.org/view.php?id=CVE-2016-2831
09 Jun 2016 — Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not ensure that the user approves the fullscreen and pointerlock settings, which allows remote attackers to cause a denial of service (UI outage), or conduct clickjacking or spoofing attacks, via a crafted web site. Mozilla Firefox en versiones anteriores a 47.0 y Firefox ESR 45.x en versiones anteriores a 45.2 no asegura que el usuario apruebe los ajustes de pantalla completa y pointerlock, lo que permite a atacantes remotos provocar una deneg... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html • CWE-254: 7PK - Security Features CWE-284: Improper Access Control •

CVE-2016-2815 – Ubuntu Security Notice USN-2993-1
https://notcve.org/view.php?id=CVE-2016-2815
09 Jun 2016 — Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Múltiples vulnerabilidades no especificadas en el motor del navegador en Mozilla Firefox en versiones anteriores a 47.0 permite a atacantes remotos provocar una denegación de servicio (corrupción de memoria y caída de aplicación) o posiblemente ejecutar código arbitrario ... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-2818 – Mozilla: Miscellaneous memory safety hazards (rv:45.2) (MFSA 2016-49)
https://notcve.org/view.php?id=CVE-2016-2818
09 Jun 2016 — Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Múltiples vulnerabilidades no especificadas en el motor del navegador en Mozilla Firefox en versiones anteriores a 47.0 y Firefox ESR 45.x en versiones anteriores a 45.2 permite a atacantes remotos provocar una denegación de servicio (corr... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-2819 – Firefox 46.0.1 - ASM.JS JIT-Spray Remote Code Execution
https://notcve.org/view.php?id=CVE-2016-2819
09 Jun 2016 — Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element. Desbordamiento de buffer basado en memoria dinámica en Mozilla Firefox en versiones anteriores a 47.0 y Firefox ESR 45.x en versiones anteriores a 45.2 permite a atacantes remotos ejecutar código arbitrario a través de fragmentos HTML5 de contexto extranjero, tal como se demuestra ... • https://packetstorm.news/files/id/146818 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2016-2821 – Mozilla: Use-after-free deleting tables from a contenteditable document (MFSA 2016-51)
https://notcve.org/view.php?id=CVE-2016-2821
09 Jun 2016 — Use-after-free vulnerability in the mozilla::dom::Element class in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2, when contenteditable mode is enabled, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by triggering deletion of DOM elements that were created in the editor. Vulnerabilidad de uso después de liberación de memoria en la clase mozilla::dom::Element en Mozilla Firefox en versiones anteriores a 47.0 y Firefox ESR 45.x en versione... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html •

CVE-2016-2828 – Mozilla: Use-after-free when textures are used in WebGL operations after recycle pool destruction (MFSA 2016-56)
https://notcve.org/view.php?id=CVE-2016-2828
09 Jun 2016 — Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool. Vulnerabilidad de uso después de liberación de memoria en Mozilla Firefox en versiones anteriores a 47.0 y Firefox ESR 45.x en versiones anteriores a 45.2 permite a atacantes remotos ejecutar código arbitrario a través de un contenido WebGL que desencadena acceso de textur... • http://lists.opensuse.org/opensuse-security-announce/2016-06/msg00014.html •

CVE-2016-0718 – expat: Out-of-bounds heap read on crafted input causing crash
https://notcve.org/view.php?id=CVE-2016-0718
18 May 2016 — Expat allows context-dependent attackers to cause a denial of service (crash) or possibly execute arbitrary code via a malformed input document, which triggers a buffer overflow. Expat permite a atacantes dependientes del contexto provocar una denegación de servicio (caída) o posiblemente ejecutar código arbitrario a través de un documento de entrada mal formado, lo que desencadena un desbordamiento de buffer. An out-of-bounds read flaw was found in the way Expat processed certain input. A remote attacker c... • https://packetstorm.news/files/id/141350 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-125: Out-of-bounds Read •