Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 23.07.2019 14:15:14
  • Zuletzt bearbeitet 21.11.2024 04:21:37

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other op...

  • EPSS 0.52%
  • Veröffentlicht 23.07.2019 14:15:13
  • Zuletzt bearbeitet 21.11.2024 04:21:36

A use-after-free vulnerability can occur when working with XMLHttpRequest (XHR) in an event loop, causing the XHR main thread to be called after it has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbir...

  • EPSS 0.52%
  • Veröffentlicht 23.07.2019 14:15:13
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free vulnerability can occur when listeners are removed from the event listener manager while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

Exploit
  • EPSS 69.41%
  • Veröffentlicht 26.04.2019 17:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

  • EPSS 51.92%
  • Veröffentlicht 26.04.2019 17:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

  • EPSS 0.21%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:20

If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an ...

  • EPSS 0.13%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:20

The Upgrade-Insecure-Requests (UIR) specification states that if UIR is enabled through Content Security Policy (CSP), navigation to a same-origin URL must be upgraded to HTTPS. Firefox will incorrectly navigate to an HTTP URL rather than perform the...

  • EPSS 1.15%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:20

In Firefox Developer Tools it is possible that pasting the result of the 'Copy as cURL' command into a command shell on macOS will cause the execution of unintended additional bash script commands if the URL was maliciously crafted. This is the resul...

  • EPSS 0.42%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:20

A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.

  • EPSS 0.34%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:20

A vulnerability exists during authorization prompting for FTP transaction where successive modal prompts are displayed and cannot be immediately dismissed. This allows for a denial of service (DOS) attack. This vulnerability affects Firefox < 66.