Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.36%
  • Veröffentlicht 10.12.2019 18:15:09
  • Zuletzt bearbeitet 21.11.2024 01:50:09

Mozilla Firefox 20.0a1 and earlier allows remote attackers to cause a denial of service (crash), related to event handling with frames.

  • EPSS 0.38%
  • Veröffentlicht 27.09.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:21:43

A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

  • EPSS 0.5%
  • Veröffentlicht 27.09.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:21:43

Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application. This can be used to write a log file to an arbitrary location such as...

  • EPSS 0.89%
  • Veröffentlicht 27.09.2019 18:15:13
  • Zuletzt bearbeitet 25.11.2025 17:50:16

It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion. This results in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60....

  • EPSS 0.06%
  • Veröffentlicht 27.09.2019 18:15:13
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware. If the Mozilla Maintenance Service is manipulated to update this unprotected location ...

  • EPSS 0.19%
  • Veröffentlicht 27.09.2019 18:15:13
  • Zuletzt bearbeitet 21.11.2024 04:21:43

When the pointer lock is enabled by a website though requestPointerLock(), no user notification is given. This could allow a malicious website to hijack the mouse pointer and confuse users. This vulnerability affects Firefox < 69.0.1.

Exploit
  • EPSS 0.99%
  • Veröffentlicht 27.09.2019 18:15:12
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cro...

  • EPSS 0.66%
  • Veröffentlicht 27.09.2019 18:15:12
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup. It is possible to pass a literal closing tag to .innerHTML on these elements, and subsequent content after that will b...

  • EPSS 0.65%
  • Veröffentlicht 27.09.2019 18:15:12
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Fire...

  • EPSS 0.35%
  • Veröffentlicht 27.09.2019 18:15:12
  • Zuletzt bearbeitet 21.11.2024 04:21:42

The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site. This includes removing any HTTP Strict Transport Security (HSTS) settings received from sites that use it. Du...