VendorsMozillafirefox43.0.4
Vulnerabilities

Mozilla Firefox 43.0.4

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2016-1944
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Published 2016-01-31 · Modified
10.0EPSS 0.037
CVE-2016-1945
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
Published 2016-01-31 · Modified
9.3EPSS 0.030
CVE-2016-1948
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.
Published 2016-01-31 · Modified
5.3EPSS 0.005
CVE-2016-1947
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
Published 2016-01-31 · Modified
4.7EPSS 0.019
CVE-2016-1943
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
Published 2016-01-31 · Modified
4.7EPSS 0.010