Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 7.5
CVE-2017-7843
When Private Browsing mode is used, it is possible for a web worker to write persistent data to IndexedDB and fingerprint a user uniquely. IndexedDB …
Debian Linux
52.5.2 / 57.0.1+
MEDIUM 6.5
CVE-2017-7844
A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which …
Firefox
57.0.1+
MEDIUM 5.3
CVE-2017-7808
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the o…
Firefox
55.0+
MEDIUM 5.3
CVE-2017-7812
If web content on a page is dragged onto portions of the browser UI, such as the tab bar, links can be opened that otherwise would not be allowed to …
Firefox
after 55.0.3
HIGH 7.5
CVE-2017-7787
Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top …
Debian Linux
55.0+
HIGH 7.5
CVE-2017-7759
Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of l…
Firefox
54.0+
MEDIUM 5.5
CVE-2017-7768
The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the s…
Firefox
52.2.0 / 54.0+
HIGH 7.5
CVE-2017-5454
A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file …
Enterprise Linux
52.1.0 / 53.0+
HIGH 7.5
CVE-2017-5425
The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some da…
Firefox
52.0+
MEDIUM 6.5
CVE-2017-5407
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted us…
Debian Linux
45.8.0 / 52.0+
MEDIUM 5.3
CVE-2017-5408
Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potenti…
Debian Linux
45.8.0 / 52.0+
MEDIUM 5.5
CVE-2017-5414
The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to inform…
Firefox
52.0+
HIGH 7.5
CVE-2017-5382
Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal inform…
Firefox
51.0+
MEDIUM 5.9
CVE-2017-5384
Proxy Auto-Config (PAC) files can specify a JavaScript function called for all URL requests with the full URL path which exposes more information tha…
Firefox
51.0+
HIGH 7.5
CVE-2017-5385
Data sent with in multipart channels, such as the multipart/x-mixed-replace MIME type, will ignore the referrer-policy response header, leading to po…
Firefox
51.0+
HIGH 7.5
CVE-2016-9904
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This …
Enterprise Linux Desktop
45.6.0 / 51.0+
HIGH 7.5
CVE-2017-5378
Hashed codes of JavaScript objects are shared between pages. This allows for pointer leaks because an object's address can be discovered through hash…
Debian Linux
45.7.0 / 51.0+
MEDIUM 5.9
CVE-2016-9074
An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NS…
Firefox
45.5.0 / 50.0+
MEDIUM 5.9
CVE-2016-5288
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This i…
Firefox
49.0.2+
HIGH 7.5
CVE-2018-12089
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabri…
Octopus Server
after 2018.5.7
MEDIUM 6.5
CVE-2018-1281
The clustered setup of Apache MXNet allows users to specify which IP address and port the scheduler will listen on via the DMLC_PS_ROOT_URI and DMLC_…
Mxnet
1.0.0+
HIGH 7.5
CVE-2018-4221
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. The issue involves the "Security" c…
Iphone Os
10.13.5 / 11.4+
MEDIUM 5.5
CVE-2018-4223
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS before 11.4 is affected. watch…
Apple Tv
4.3.1 / 10.13.5+
MEDIUM 5.5
CVE-2018-4224
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is aff…
Apple Tv
4.3.1 / 7.5+
MEDIUM 5.5
CVE-2018-4226
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. iCloud before 7.5 on Windows is aff…
Iphone Os
4.3.1 / 7.5+
MEDIUM 5.5
CVE-2018-4141
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Intel Graphics Driver" component. It all…
Mac Os X
10.13.5+
MEDIUM 5.5
CVE-2018-4159
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Graphics Drivers" component. It allows a…
Mac Os X
10.13.5+
MEDIUM 5.5
CVE-2018-4171
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Bluetooth" component. It allows attacker…
Mac Os X
10.13.5+
HIGH 7.8
CVE-2018-4196
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Accessibility Framework" component. It a…
Mac Os X
10.13.5+
MEDIUM 5.5
CVE-2012-0433
The install-chef-suse.sh script shipped with crowbar before 2012-10-02 is creating files containing confidential data with insecure permissions, allo…
Crowbar
after 1.0