VDB
GCVE-VVD-MAGEIA-2017-59
GCVE-VVD-MAGEIA-2017-59
Advisory Published
Updated Iceape packages derived from Seamonkey include security fixes from
Mozilla Firefox:
Heap-based buffer overflow in the
nsCaseTransformTextRunFactory::TransformString function in Seamonkey
before 2.46 allows remote attackers to cause a denial of service (boolean
out-of-bounds write) or possibly have unspecified other impact via Unicode
characters that are mishandled during text conversion. (CVE-2016-5270)
The PropertyProvider::GetSpacingInternal function in Seamonkey before 2.46
allows remote attackers to cause a denial of service (out-of-bounds read
and application crash) via text runs in conjunction with a
"display: contents" Cascading Style Sheets (CSS) property. (CVE-2016-5271)
The nsImageGeometryMixin class in Seamonkey before 2.46 does not properly
perform a cast of an unspecified variable during handling of INPUT
elements, which allows remote attackers to execute arbitrary code via a
crafted web site. (CVE-2016-5272)
Use-after-free vulnerability in the
mozilla::a11y::DocAccessible::ProcessInvalidationList function in
Seamonkey before 2.46 allows remote attackers to execute arbitrary code
or cause a denial of service (heap memory corruption) via an aria-owns
attribute. (CVE-2016-5276)
Use-after-free vulnerability in the nsFrameManager::CaptureFrameState
function in Seamonkey before 2.46 allows remote attackers to execute
arbitrary code by leveraging improper interaction between restyling and
the Web Animations model implementation. (CVE-2016-5274)
Use-after-free vulnerability in the nsRefreshDriver::Tick function in
Seamonkey before 2.46 allows remote attackers to execute arbitrary code or
cause a denial of service (heap memory corruption) by leveraging improper
interaction between timeline destruction and the Web Animations model
implementation. (CVE-2016-5277)
Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in
Seamonkey before 2.46 allows remote attackers to execute arbitrary code
via a crafted image data that is mishandled during the encoding of an
image frame to an image. (CVE-2016-5278)
Use-after-free vulnerability in the
mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in
Seamonkey before 2.46 allows remote attackers to execute arbitrary code
via bidirectional text. (CVE-2016-5280)
Use-after-free vulnerability in the DOMSVGLength class in Seamonkey before
2.46 allows remote attackers to execute arbitrary code by leveraging
improper interaction between JavaScript code and an SVG document.
(CVE-2016-5281)
Seamonkey before 2.46 relies on unintended expiration dates for Preloaded
Public Key Pinning, which allows man-in-the-middle attackers to spoof
add-on updates by leveraging possession of an X.509 server certificate for
addons.mozilla.org signed by an arbitrary built-in Certification
Authority. (CVE-2016-5284)
Multiple unspecified vulnerabilities in the browser engine in Seamonkey
before 2.46 allow remote attackers to cause a denial of service (memory
corruption and application crash) or possibly execute arbitrary code via
unknown vectors. (CVE-2016-5257)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | digikam | 0 (affected), 5.5.0-2.1.mga6 (unaffected) | — |
| Mageia | iceape | 0 (affected), 2.46-1.mga5 (unaffected), 0 (affected), 2.46-1.mga5 (unaffected) | — |
Aliases
CVE-2016-2827CVE-2016-5278CVE-2016-5272CVE-2016-5257CVE-2016-5270CVE-2016-5280CVE-2016-5274CVE-2016-5277CVE-2016-5284CVE-2016-5271CVE-2016-5281CVE-2016-5276
Transitive aliases
VVD-MAGEIA-2016-329GHSA-2hcj-223m-pqx5CVE-2016-5261GHSA-jf8q-fmcm-x642BDU:2016-01915EUVD-2016-6201GHSA-w8fm-f723-jm45EUVD-2016-6231EUVD-2016-6208GHSA-3vmp-cwhr-32wmBDU:2021-04197EUVD-2016-6223EUVD-2016-6221EUVD-2016-3900GHSA-6vr6-9p4m-qv5vEUVD-2016-6228GHSA-465v-39xq-8c56BDU:2021-04047GHSA-9vc8-w555-j964BDU:2021-04041EUVD-2016-6222GHSA-qcqq-5qh9-xq8vVVD-MAGEIA-2016-336CVE-2016-5250EUVD-2016-6212GHSA-jrqh-qj76-c265BDU:2016-01924EUVD-2016-6225GHSA-fw5c-gh38-g4ggGHSA-25gr-ph8w-33hcGHSA-rr7w-29gf-6ffpEUVD-2016-6227GHSA-2fqh-hxv3-hqmxEUVD-2016-6235GHSA-942w-8v4f-46qwEUVD-2016-6229EUVD-2016-6232
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.