Mozilla

Firefox

3041 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.11%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

The Mozilla Windows updater can be called by a non-privileged user to delete an arbitrary local file by passing a special path to the callback parameter through the Mozilla Maintenance Service, which has privileged access. Note: This attack requires ...

Exploit
  • EPSS 2.53%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 25.11.2025 17:50:16

Memory corruption resulting in a potentially exploitable crash during garbage collection of JavaScript due errors in how incremental sweeping is managed for memory cleanup. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52...

Exploit
  • EPSS 0.74%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:34

A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This is...

  • EPSS 0.36%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:34

A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52.

Exploit
  • EPSS 0.56%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:34

A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.

  • EPSS 0.13%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:34

The file picker dialog can choose and display the wrong local default directory when instantiated. On some operating systems, this can lead to information disclosure, such as the operating system or the local account name. This vulnerability affects ...

Exploit
  • EPSS 29.15%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:34

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.

Exploit
  • EPSS 0.86%
  • Veröffentlicht 11.06.2018 21:29:04
  • Zuletzt bearbeitet 21.11.2024 03:27:34

In certain circumstances a networking event listener can be prematurely released. This appears to result in a null dereference in practice. This vulnerability affects Firefox < 52 and Thunderbird < 52.

  • EPSS 1.8%
  • Veröffentlicht 11.06.2018 21:29:03
  • Zuletzt bearbeitet 25.11.2025 17:50:16

A potential use-after-free found through fuzzing during DOM manipulation of SVG content. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

  • EPSS 1.26%
  • Veröffentlicht 11.06.2018 21:29:03
  • Zuletzt bearbeitet 21.11.2024 03:27:29

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerabilit...