Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.19%
  • Veröffentlicht 26.04.2019 17:29:01
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Mozilla developers and community members reported memory safety bugs present in Firefox 65, Firefox ESR 60.5, and Thunderbird 60.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these coul...

  • EPSS 0.44%
  • Veröffentlicht 26.04.2019 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:52:18

Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. Th...

  • EPSS 0.76%
  • Veröffentlicht 26.04.2019 17:29:01
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free vulnerability can occur when a raw pointer to a DOM element on a page is obtained using JavaScript and the element is then removed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunde...

Exploit
  • EPSS 39.3%
  • Veröffentlicht 26.04.2019 17:29:01
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The type inference system allows the compilation of functions that can cause type confusions between arbitrary objects when compiled through the IonMonkey just-in-time (JIT) compiler and when the constructor function is entered through on-stack repla...

Exploit
  • EPSS 19.72%
  • Veröffentlicht 26.04.2019 17:29:01
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitab...

  • EPSS 0.31%
  • Veröffentlicht 26.04.2019 17:29:01
  • Zuletzt bearbeitet 21.11.2024 04:52:19

A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. This vulnerability could allow an attacker to create an arbitrary value in compiled JavaScript, for whi...

  • EPSS 0.25%
  • Veröffentlicht 26.04.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:56:04

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious s...

  • EPSS 0.83%
  • Veröffentlicht 26.04.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 03:56:04

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0....

  • EPSS 0.56%
  • Veröffentlicht 26.04.2019 17:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:09

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

  • EPSS 0.35%
  • Veröffentlicht 26.04.2019 14:29:00
  • Zuletzt bearbeitet 21.11.2024 04:08:16

A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.