Mozilla

Firefox

2867 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.51%
  • Veröffentlicht 11.06.2018 21:29:08
  • Zuletzt bearbeitet 21.11.2024 03:32:38

An error in the "WindowsDllDetourPatcher" where a RWX ("Read/Write/Execute") 4k block is allocated but never protected, violating DEP protections. Note: This attack only affects Windows operating systems. Other operating systems are not affected. Thi...

Exploit
  • EPSS 2.02%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:40

A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Fi...

  • EPSS 1.07%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:40

A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been ...

  • EPSS 0.77%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:40

Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of the addressbar as displayed to users. Note: This attack only affects Firefox for Android. Other opera...

  • EPSS 2.02%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:40

During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firef...

Exploit
  • EPSS 23.65%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:40

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird...

Exploit
  • EPSS 0.62%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:40

If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (...

  • EPSS 1.3%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:41

A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

  • EPSS 2.32%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:41

An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.

  • EPSS 5.64%
  • Veröffentlicht 11.06.2018 21:29:07
  • Zuletzt bearbeitet 21.11.2024 03:27:41

Fixed potential buffer overflows in generated Firefox code due to CVE-2016-6354 issue in Flex. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.