Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.81%
  • Veröffentlicht 11.06.2018 21:29:10
  • Zuletzt bearbeitet 21.11.2024 03:32:44

The "instanceof" operator can bypass the Xray wrapper mechanism. When called on web content from the browser itself or an extension the web content can provide its own result for that operator, possibly tricking the browser or extension into mishandl...

Exploit
  • EPSS 2.73%
  • Veröffentlicht 11.06.2018 21:29:10
  • Zuletzt bearbeitet 21.11.2024 03:32:44

A vulnerability where WebExtensions can download and attempt to open a file of some non-executable file types. This can be triggered without specific user interaction for the file download and open actions. This could be used to trigger known vulnera...

  • EPSS 0.61%
  • Veröffentlicht 11.06.2018 21:29:10
  • Zuletzt bearbeitet 21.11.2024 03:32:44

The AES-GCM implementation in WebCrypto API accepts 0-length IV when it should require a length of 1 according to the NIST Special Publication 800-38D specification. This might allow for the authentication key to be determined in some instances. This...

Exploit
  • EPSS 6.9%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 21.11.2024 03:32:39

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability a...

Exploit
  • EPSS 5.48%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 21.11.2024 03:32:39

A use-after-free vulnerability can occur when reading an image observer during frame reconstruction after the observer has been freed. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3,...

Exploit
  • EPSS 8.84%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A buffer overflow can occur when manipulating Accessible Rich Internet Applications (ARIA) attributes within the DOM. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55...

Exploit
  • EPSS 8.93%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 21.11.2024 03:32:39

A buffer overflow can occur when the image renderer attempts to paint non-displayable SVG elements. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

Exploit
  • EPSS 1.03%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 21.11.2024 03:32:39

Same-origin policy protections can be bypassed on pages with embedded iframes during page reloads, allowing the iframes to access content on the top level page, leading to information disclosure. This vulnerability affects Thunderbird < 52.3, Firefox...

Exploit
  • EPSS 2.02%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 21.11.2024 03:32:39

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vul...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 21.11.2024 03:32:39

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.