Mozilla

Firefox

3041 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.02%
  • Veröffentlicht 23.07.2019 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:52:21

If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sy...

  • EPSS 38.25%
  • Veröffentlicht 23.07.2019 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:52:22

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with Unboxed...

  • EPSS 0.19%
  • Veröffentlicht 23.07.2019 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:52:22

Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and ...

  • EPSS 0.34%
  • Veröffentlicht 23.07.2019 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:52:22

A race condition is present in the crash generation server used to generate data for the crash reporter. This issue can lead to a use-after-free in the main process, resulting in a potentially exploitable crash and a sandbox escape. *Note: this vulne...

  • EPSS 0.55%
  • Veröffentlicht 23.07.2019 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:52:22

A vulnerability where a JavaScript compartment mismatch can occur while working with the fetch API, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

  • EPSS 0.55%
  • Veröffentlicht 23.07.2019 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:52:22

A use-after-free vulnerability can occur in the chrome event handler when it is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

  • EPSS 0.42%
  • Veröffentlicht 23.07.2019 14:15:17
  • Zuletzt bearbeitet 21.11.2024 04:52:22

A use-after-free vulnerability can occur in AssertWorkerThread due to a race condition with shared workers. This results in a potentially exploitable crash. This vulnerability affects Firefox < 67.

  • EPSS 0.45%
  • Veröffentlicht 23.07.2019 14:15:16
  • Zuletzt bearbeitet 25.11.2025 17:50:16

When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Fir...

  • EPSS 0.74%
  • Veröffentlicht 23.07.2019 14:15:16
  • Zuletzt bearbeitet 21.11.2024 04:21:39

Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability af...

Exploit
  • EPSS 0.57%
  • Veröffentlicht 23.07.2019 14:15:16
  • Zuletzt bearbeitet 21.11.2024 04:21:39

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.