Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.2%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:20

When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects...

  • EPSS 0.09%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:21

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which s...

Exploit
  • EPSS 0.51%
  • Veröffentlicht 26.04.2019 17:29:03
  • Zuletzt bearbeitet 21.11.2024 04:52:21

If the source for resources on a page is through an FTP connection, it is possible to trigger a series of modal alert messages for these resources through invalid credentials or locations. These messages cannot be immediately dismissed, allowing for ...

  • EPSS 0.44%
  • Veröffentlicht 26.04.2019 17:29:02
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A vulnerability was discovered where specific command line arguments are not properly discarded during Firefox invocation as a shell handler for URLs. This could be used to retrieve and execute files whose location is supplied through these command l...

  • EPSS 0.76%
  • Veröffentlicht 26.04.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:52:19

A vulnerability where type-confusion in the IonMonkey just-in-time (JIT) compiler could potentially be used by malicious JavaScript to trigger a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Fir...

  • EPSS 0.76%
  • Veröffentlicht 26.04.2019 17:29:02
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free vulnerability can occur when the SMIL animation controller incorrectly registers with the refresh driver twice when only a single registration is expected. When a registration is later freed with the removal of the animation controll...

  • EPSS 0.5%
  • Veröffentlicht 26.04.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:52:19

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 6...

  • EPSS 0.19%
  • Veröffentlicht 26.04.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:52:19

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that locat...

  • EPSS 0.24%
  • Veröffentlicht 26.04.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:52:19

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.

  • EPSS 0.39%
  • Veröffentlicht 26.04.2019 17:29:02
  • Zuletzt bearbeitet 21.11.2024 04:52:20

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself...