Mozilla

Firefox

2867 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.46%
  • Published 22.09.2016 22:59:18
  • Last modified 12.04.2025 10:46:40

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X....

  • EPSS 0.45%
  • Published 22.09.2016 22:59:16
  • Last modified 12.04.2025 10:46:40

Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.

  • EPSS 1.74%
  • Published 22.09.2016 22:59:15
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code a...

  • EPSS 1.7%
  • Published 22.09.2016 22:59:14
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirec...

  • EPSS 0.4%
  • Published 22.09.2016 22:59:13
  • Last modified 12.04.2025 10:46:40

Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.

  • EPSS 1.36%
  • Published 22.09.2016 22:59:12
  • Last modified 12.04.2025 10:46:40

Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled ...

  • EPSS 1.35%
  • Published 22.09.2016 22:59:11
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corrup...

  • EPSS 1.15%
  • Published 22.09.2016 22:59:10
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the mozilla::a11y::DocAccessible::ProcessInvalidationList function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denia...

  • EPSS 2.58%
  • Published 22.09.2016 22:59:08
  • Last modified 12.04.2025 10:46:40

Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rende...

  • EPSS 1.51%
  • Published 22.09.2016 22:59:07
  • Last modified 12.04.2025 10:46:40

Use-after-free vulnerability in the nsFrameManager::CaptureFrameState function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction b...