Mozilla

Firefox

2867 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.76%
  • Veröffentlicht 23.07.2019 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:21:38

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.

  • EPSS 0.77%
  • Veröffentlicht 23.07.2019 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:21:39

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderb...

  • EPSS 0.58%
  • Veröffentlicht 23.07.2019 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:21:39

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window...

Exploit
  • EPSS 5.03%
  • Veröffentlicht 23.07.2019 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:21:39

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68,...

  • EPSS 0.73%
  • Veröffentlicht 23.07.2019 14:15:15
  • Zuletzt bearbeitet 21.11.2024 04:21:39

Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stre...

  • EPSS 0.6%
  • Veröffentlicht 23.07.2019 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:21:36

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. ...

  • EPSS 0.4%
  • Veröffentlicht 23.07.2019 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:21:36

A vulnerability exists in the Windows sandbox where an uninitialized value in memory can be leaked to a renderer from a broker when making a call to access an otherwise unavailable file. This results in the potential leaking of information stored at ...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 23.07.2019 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:21:36

A custom cursor defined by scripting on a site can position itself over the addressbar to spoof the actual cursor when it should not be allowed outside of the primary web content area. This could be used by a malicious site to trick users into clicki...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 23.07.2019 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:21:36

Files with the .JNLP extension used for "Java web start" applications are not treated as executable content for download prompts even though they can be executed if Java is installed on the local system. This could allow users to mistakenly launch an...

  • EPSS 0.2%
  • Veröffentlicht 23.07.2019 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:21:36

If the ALT and "a" keys are pressed when users receive an extension installation prompt, the extension will be installed without the install prompt delay that keeps the prompt visible in order for users to accept or decline the installation. A malici...