Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.72%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:32

A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.

  • EPSS 0.69%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:32

A maliciously crafted page loaded to the sidebar through a bookmark can reference a privileged chrome window and engage in limited JavaScript operations violating cross-origin protections. This vulnerability affects Firefox < 50.

  • EPSS 0.26%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:32

Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.

  • EPSS 0.37%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:32

When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected. This vulne...

  • EPSS 0.81%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:32

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.

  • EPSS 1.22%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 25.11.2025 17:50:16

An existing mitigation of timing side-channel attacks is insufficient in some circumstances. This issue is addressed in Network Security Services (NSS) 3.26.1. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.

  • EPSS 2.55%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:33

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission....

  • EPSS 0.53%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:33

An issue where a "<select>" dropdown menu can be used to cover location bar content, resulting in potential spoofing attacks. This attack requires e10s to be enabled in order to function. This vulnerability affects Firefox < 50.

  • EPSS 0.17%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:33

Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulne...

Exploit
  • EPSS 1.18%
  • Veröffentlicht 11.06.2018 21:29:01
  • Zuletzt bearbeitet 21.11.2024 03:00:33

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin set...