Page 28 of 471 results (0.068 seconds)

CVSS: 9.8EPSS: 2%CPEs: 3EXPL: 0

11 Jul 2019 — A sandbox escape was discovered in Firefox. • http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html • CWE-416: Use After Free •

CVSS: 6.1EPSS: 1%CPEs: 3EXPL: 0

11 Jul 2019 — A sandbox escape was discovered in Firefox. • http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 5%CPEs: 7EXPL: 1

11 Jul 2019 — A sandbox escape was discovered in Firefox. • http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html • CWE-116: Improper Encoding or Escaping of Output CWE-138: Improper Neutralization of Special Elements •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

11 Jul 2019 — A sandbox escape was discovered in Firefox. • http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html • CWE-125: Out-of-bounds Read •

CVSS: 7.5EPSS: 0%CPEs: 3EXPL: 0

11 Jul 2019 — A sandbox escape was discovered in Firefox. • http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 6.5EPSS: 32%CPEs: 8EXPL: 2

11 Jul 2019 — A sandbox escape was discovered in Firefox. • https://github.com/alidnf/CVE-2019-11730 • CWE-829: Inclusion of Functionality from Untrusted Control Sphere •

CVSS: 8.3EPSS: 1%CPEs: 7EXPL: 2

10 Jul 2019 — As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. ... A sandbox escape was discovered in Firefox. • http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00055.html • CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') CWE-807: Reliance on Untrusted Inputs in a Security Decision •

CVSS: 10.0EPSS: 65%CPEs: 3EXPL: 4

24 Jun 2019 — Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. • https://packetstorm.news/files/id/165816 • CWE-20: Improper Input Validation CWE-270: Privilege Context Switching Error •

CVSS: 9.0EPSS: 0%CPEs: 10EXPL: 0

15 May 2019 — An elevation of privilege vulnerability exists in Microsoft Edge that could allow an attacker to escape from the AppContainer sandbox in the browser, aka 'Microsoft Edge Elevation of Privilege Vulnerability'. Hay una vulnerabilidad de elevación de privilegios en Microsoft Edge que podría permitir a un atacante escapar de AppContainer sandbox en el navegador, también conocida como "vulnerabilidad de elevación de privilegios de Microsoft Edge". This vulnerability allows remote attackers to escalate privileges... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0938 •

CVSS: 9.3EPSS: 0%CPEs: 1EXPL: 0

14 May 2019 — A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Mojave 10.14.5. An application may be able to execute arbitrary code with system privileges. Un problema de corrupción de memoria fue abordado mejorando el manejo de la memoria. Este problema es corregido en macOS Mojave versión 10.14.5. • https://support.apple.com/HT210119 • CWE-787: Out-of-bounds Write •