Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.05%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

JIT-spray targeting asm.js combined with a heap spray allows for a bypass of ASLR and DEP protections leading to potential memory corruption attacks. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45....

Exploit
  • EPSS 2.31%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A crash triggerable by web content in which an "ErrorResult" references unassigned memory due to a logic error. The resulting crash may be exploitable. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 4...

  • EPSS 2.66%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free can occur when events are fired for a "FontFace" object after the object has been already been destroyed while working with fonts. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR ...

  • EPSS 0.54%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:32

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thun...

Exploit
  • EPSS 23.67%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 4...

Exploit
  • EPSS 2.35%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

Exploit
  • EPSS 0.74%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:32

A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Exploit
  • EPSS 1.1%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violate...

Exploit
  • EPSS 1.07%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Video files loaded video captions cross-origin without checking for the presence of CORS headers permitting such cross-origin use, leading to potential information disclosure for video captions. This vulnerability affects Firefox < 52, Firefox ESR < ...

Exploit
  • EPSS 0.11%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires ...