CVE-2023-23604
- EPSS 0.03%
- Published 02.06.2023 17:15:10
- Last modified 10.01.2025 18:15:16
A duplicate <code>SystemPrincipal</code> object could be created when parsing a non-system html document via <code>DOMParser::ParseFromSafeString</code>. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109.
CVE-2023-23605
- EPSS 0.14%
- Published 02.06.2023 17:15:10
- Last modified 10.01.2025 18:15:16
Memory safety bugs present in Firefox 108 and Firefox ESR 102.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects ...
CVE-2023-23606
- EPSS 0.16%
- Published 02.06.2023 17:15:10
- Last modified 10.01.2025 18:15:17
Memory safety bugs present in Firefox 108. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 109.
CVE-2019-17003
- EPSS 0.54%
- Published 16.02.2023 22:15:10
- Last modified 19.03.2025 16:15:12
Scanning a QR code that contained a javascript: URL would have resulted in the Javascript being executed.
CVE-2020-12413
- EPSS 0.12%
- Published 16.02.2023 22:15:10
- Last modified 19.03.2025 16:15:14
The Raccoon attack is a timing attack on DHE ciphersuites inherit in the TLS specification. To mitigate this vulnerability, Firefox disabled support for DHE ciphersuites.
CVE-2022-46885
- EPSS 0.37%
- Published 22.12.2022 20:15:48
- Last modified 15.04.2025 15:16:06
Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have b...
CVE-2022-46879
- EPSS 0.41%
- Published 22.12.2022 20:15:47
- Last modified 15.04.2025 15:16:06
Mozilla developers and community members Lukas Bernhard, Gabriele Svelto, Randell Jesup, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 107. Some of these bugs showed evidence of memory corruption and we presume that with...
CVE-2022-46880
- EPSS 0.14%
- Published 22.12.2022 20:15:47
- Last modified 15.04.2025 14:15:38
A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.<br />*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the ori...
CVE-2022-46881
- EPSS 0.19%
- Published 22.12.2022 20:15:47
- Last modified 15.04.2025 14:15:38
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was ...
CVE-2022-46882
- EPSS 0.24%
- Published 22.12.2022 20:15:47
- Last modified 15.04.2025 15:16:06
A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.