Mozilla

Firefox

2939 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.62%
  • Veröffentlicht 15.04.2019 12:31:08
  • Zuletzt bearbeitet 21.11.2024 03:32:37

Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

Exploit
  • EPSS 0.56%
  • Veröffentlicht 15.04.2019 12:31:08
  • Zuletzt bearbeitet 21.11.2024 03:32:38

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 15.04.2019 12:31:08
  • Zuletzt bearbeitet 21.11.2024 03:32:38

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

Exploit
  • EPSS 0.5%
  • Veröffentlicht 15.04.2019 12:31:08
  • Zuletzt bearbeitet 21.11.2024 03:32:38

Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

Exploit
  • EPSS 0.62%
  • Veröffentlicht 12.04.2019 18:29:00
  • Zuletzt bearbeitet 21.11.2024 03:32:37

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

  • EPSS 0.41%
  • Veröffentlicht 28.02.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:45:08

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not ...

  • EPSS 0.3%
  • Veröffentlicht 28.02.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:45:08

In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox ...

  • EPSS 0.88%
  • Veröffentlicht 28.02.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:45:08

Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.

  • EPSS 0.36%
  • Veröffentlicht 28.02.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:45:08

The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windo...

  • EPSS 0.5%
  • Veröffentlicht 28.02.2019 18:29:01
  • Zuletzt bearbeitet 21.11.2024 03:45:09

If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.