Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.44%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free vulnerability can occur while re-computing layout for a "marquee" element during window resizing where the updated style object is freed while still in use. This results in a potentially exploitable crash. This vulnerability affects ...

Exploit
  • EPSS 2.41%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free vulnerability can occur when manipulating the DOM during the resize event of an image element. If these elements have been freed due to a lack of strong references, a potentially exploitable crash may occur when the freed elements ar...

Exploit
  • EPSS 1.1%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 25.11.2025 17:50:16

When a page's content security policy (CSP) header contains a "sandbox" directive, other directives are ignored. This results in the incorrect enforcement of CSP. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

  • EPSS 0.69%
  • Veröffentlicht 11.06.2018 21:29:09
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memor...

  • EPSS 1.97%
  • Veröffentlicht 11.06.2018 21:29:08
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free and use-after-scope vulnerability when logging errors from headers for XML HTTP Requests (XHR). This could result in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2...

  • EPSS 1.97%
  • Veröffentlicht 11.06.2018 21:29:08
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free vulnerability in IndexedDB when one of its objects is destroyed in memory while a method on it is still being executed. This results in a potentially exploitable crash. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and...

Exploit
  • EPSS 1.77%
  • Veröffentlicht 11.06.2018 21:29:08
  • Zuletzt bearbeitet 25.11.2025 17:50:16

An out-of-bounds read vulnerability with the Opus encoder when the number of channels in an audio stream changes while the encoder is in use. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

Exploit
  • EPSS 0.32%
  • Veröffentlicht 11.06.2018 21:29:08
  • Zuletzt bearbeitet 21.11.2024 03:32:36

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Andro...

Exploit
  • EPSS 0.14%
  • Veröffentlicht 11.06.2018 21:29:08
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The Mozilla Windows updater modifies some files to be updated by reading the original file and applying changes to it. The location of the original file can be altered by a malicious user by passing a special path to the callback parameter through th...

  • EPSS 0.09%
  • Veröffentlicht 11.06.2018 21:29:08
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junct...