Mozilla

Focus

17 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.14%
  • Published 02.06.2023 17:15:12
  • Last modified 10.01.2025 19:15:36

Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaff...

  • EPSS 0.14%
  • Published 02.06.2023 17:15:12
  • Last modified 21.11.2024 07:57:15

Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 1...

  • EPSS 0.13%
  • Published 02.06.2023 17:15:12
  • Last modified 21.11.2024 07:57:15

When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. ...

  • EPSS 0.12%
  • Published 02.06.2023 17:15:12
  • Last modified 21.11.2024 07:57:15

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox...

  • EPSS 0.19%
  • Published 02.06.2023 17:15:12
  • Last modified 21.11.2024 07:57:15

Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

  • EPSS 0.14%
  • Published 02.06.2023 17:15:12
  • Last modified 21.11.2024 07:57:15

An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for ...

  • EPSS 0.1%
  • Published 02.06.2023 17:15:12
  • Last modified 21.11.2024 07:57:15

Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, F...