Mozilla

Firefox

2867 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.3%
  • Veröffentlicht 14.05.2024 18:15:15
  • Zuletzt bearbeitet 04.04.2025 14:26:28

When a network error occurred during page load, the prior content could have remained in view with a blank URL bar. This could have been used to obfuscate a spoofed web site. This vulnerability affects Firefox < 126.

  • EPSS 0.04%
  • Veröffentlicht 14.05.2024 18:15:15
  • Zuletzt bearbeitet 28.03.2025 19:15:22

The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.

Exploit
  • EPSS 0.07%
  • Veröffentlicht 14.05.2024 18:15:15
  • Zuletzt bearbeitet 01.04.2025 17:56:23

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerabi...

Exploit
  • EPSS 0.71%
  • Veröffentlicht 14.05.2024 18:15:14
  • Zuletzt bearbeitet 01.04.2025 18:00:09

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

  • EPSS 0.69%
  • Veröffentlicht 14.05.2024 18:15:14
  • Zuletzt bearbeitet 01.04.2025 17:46:33

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affect...

Exploit
  • EPSS 0.43%
  • Veröffentlicht 14.05.2024 18:15:14
  • Zuletzt bearbeitet 01.04.2025 17:46:09

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 14.05.2024 18:15:14
  • Zuletzt bearbeitet 01.04.2025 17:54:27

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

  • EPSS 0.15%
  • Veröffentlicht 14.05.2024 18:15:13
  • Zuletzt bearbeitet 04.04.2025 14:27:03

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue on...

  • EPSS 0.33%
  • Veröffentlicht 14.05.2024 18:15:13
  • Zuletzt bearbeitet 04.04.2025 14:26:43

Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.*...

Exploit
  • EPSS 0.56%
  • Veröffentlicht 14.05.2024 18:15:13
  • Zuletzt bearbeitet 01.04.2025 17:47:50

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11,...