Mozilla

Firefox

3041 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 22.09.2016 22:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.

  • EPSS 1.25%
  • Veröffentlicht 06.09.2016 10:59:01
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-pa...

  • EPSS 1.25%
  • Veröffentlicht 06.09.2016 10:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-par...

  • EPSS 0.44%
  • Veröffentlicht 05.08.2016 01:59:24
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonst...

  • EPSS 0.37%
  • Veröffentlicht 05.08.2016 01:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set.

  • EPSS 0.43%
  • Veröffentlicht 05.08.2016 01:59:22
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site.

  • EPSS 0.26%
  • Veröffentlicht 05.08.2016 01:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allow user-assisted remote attackers to bypass the Same Origin Policy, and conduct Universal XSS (UXSS) attacks or read arbitrary files, by arranging for the presence of a crafted HTML docu...

Exploit
  • EPSS 1.01%
  • Veröffentlicht 05.08.2016 01:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Use-after-free vulnerability in the nsNodeUtils::NativeAnonymousChildListChange function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corru...

  • EPSS 0.68%
  • Veröffentlicht 05.08.2016 01:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confu...

  • EPSS 0.29%
  • Veröffentlicht 05.08.2016 01:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 process JavaScript event-handler attributes of a MARQUEE element within a sandboxed IFRAME element that lacks the sandbox="allow-scripts" attribute value, which makes it easier for remote a...