
CVE-2015-0808 – Gentoo Linux Security Advisory 201512-10
https://notcve.org/view.php?id=CVE-2015-0808
01 Apr 2015 — The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors. La función webrtc::VPMContentAnalysis::Release en la implementación WebRTC en Mozilla Firefox anterior a 37.0 utiliza acercamientos incompatibles para quitar la reserva de memoria para arrays de un tipo simple, ... • http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html • CWE-17: DEPRECATED: Code •

CVE-2015-0803 – Gentoo Linux Security Advisory 201512-10
https://notcve.org/view.php?id=CVE-2015-0803
01 Apr 2015 — The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document. La función HTMLSourceElement::AfterSetAttr en Mozilla Firefox anterior a 37.0 no limita correctamente el tipo de datos originales de un valor asignado durante la configuración de los ... • http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-0804 – Gentoo Linux Security Advisory 201512-10
https://notcve.org/view.php?id=CVE-2015-0804
01 Apr 2015 — The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element. La función HTMLSourceElement::BindToTree en Mozilla Firefox anterior a 37.0 no limita correctamente un tipo de datos después de omitir la validación del espacio pa... • http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-0815 – Mozilla: Miscellaneous memory safety hazards (rv:31.6) (MFSA 2015-30)
https://notcve.org/view.php?id=CVE-2015-0815
01 Apr 2015 — Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. Múltiples vulnerabilidades no especificadas en el motor del navegador en Mozilla Firefox anterior a 37.0, Firefox ESR 31.x anterior a 31.6, y Thunderbird anterior a 31.6 permiten a atacantes remotos causar una den... • http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html • CWE-122: Heap-based Buffer Overflow •

CVE-2015-0813 – Mozilla: Use-after-free when using the Fluendo MP3 GStreamer plugin (MFSA 2015-31)
https://notcve.org/view.php?id=CVE-2015-0813
01 Apr 2015 — Use-after-free vulnerability in the AppendElements function in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 on Linux, when the Fluendo MP3 plugin for GStreamer is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted MP3 file. Vulnerabilidad de uso después de liberación en la función AppendElements en Mozilla Firefox anterior a 37.0, Firefox ESR 31.x anterior a 31.6, y Thunderbird anterior a 31.6 ... • http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00003.html • CWE-416: Use After Free •

CVE-2015-0818 – Mozilla Firefox SVG DOMAttrModified Same-Origin Policy Bypass Vulnerability
https://notcve.org/view.php?id=CVE-2015-0818
23 Mar 2015 — Mozilla Firefox before 36.0.4, Firefox ESR 31.x before 31.5.3, and SeaMonkey before 2.33.1 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving SVG hash navigation. Mozilla Firefox anterior a 36.0.4, Firefox ESR 31.x anterior a 31.5.3, y SeaMonkey anterior a 2.33.1 permiten a atacantes remotos evadir Same Origin Policy y ejecutar código JavaScript arbitrario con privilegios chrome a través de vectores que involucran la nav... • http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00026.html • CWE-264: Permissions, Privileges, and Access Controls •

CVE-2015-0817 – Mozilla Firefox Bounds Check Elimination Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2015-0817
23 Mar 2015 — The asm.js implementation in Mozilla Firefox before 36.0.3, Firefox ESR 31.x before 31.5.2, and SeaMonkey before 2.33.1 does not properly determine the cases in which bounds checking may be safely skipped during JIT compilation and heap access, which allows remote attackers to read or write to unintended memory locations, and consequently execute arbitrary code, via crafted JavaScript. La implementación asm.js en Mozilla Firefox anterior a 36.0.3, Firefox ESR 31.x anterior a 31.5.2, y SeaMonkey anterior a 2... • http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00026.html • CWE-17: DEPRECATED: Code CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVE-2015-0828 – Gentoo Linux Security Advisory 201504-01
https://notcve.org/view.php?id=CVE-2015-0828
25 Feb 2015 — Double free vulnerability in the nsXMLHttpRequest::GetResponse function in Mozilla Firefox before 36.0, when a nonstandard memory allocator is used, allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted JavaScript code that makes an XMLHttpRequest call with zero bytes of data. Vulnerabilidad de doble liberación en la función nsXMLHttpRequest::GetResponse en Mozilla Firefox anterior a 36.0, cuando un asignador de memoria no estándar está utilizado... • http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.html •

CVE-2015-0833 – Gentoo Linux Security Advisory 201504-01
https://notcve.org/view.php?id=CVE-2015-0833
25 Feb 2015 — Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 on Windows, when the Maintenance Service is not used, allow local users to gain privileges via a Trojan horse DLL in (1) the current working directory or (2) a temporary directory, as demonstrated by bcrypt.dll. Múltiples vulnerabilidades de rutas de búsqueda no confiables en updater.exe en Mozilla Firefox anterior a 36.0, Firefox ESR 31.x anterior a 31.5, y... • http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00026.html •

CVE-2015-0825 – Ubuntu Security Notice USN-2505-2
https://notcve.org/view.php?id=CVE-2015-0825
25 Feb 2015 — Stack-based buffer underflow in the mozilla::MP3FrameParser::ParseBuffer function in Mozilla Firefox before 36.0 allows remote attackers to obtain sensitive information from process memory via a malformed MP3 file that improperly interacts with memory allocation during playback. Subdesbordamiento de buffer basado en pila en la función mozilla::MP3FrameParser::ParseBuffer en Mozilla Firefox anterior a 36.0 permite a atacantes remotos obtener información sensible de la memoria de procesos a través de un fiche... • http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00000.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •