Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.54%
  • Veröffentlicht 24.09.2015 04:59:22
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via...

  • EPSS 1.54%
  • Veröffentlicht 24.09.2015 04:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact v...

  • EPSS 1.54%
  • Veröffentlicht 24.09.2015 04:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknow...

  • EPSS 0.26%
  • Veröffentlicht 24.09.2015 04:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* re...

  • EPSS 0.21%
  • Veröffentlicht 24.09.2015 04:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an...

  • EPSS 1.54%
  • Veröffentlicht 24.09.2015 04:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

  • EPSS 1.01%
  • Veröffentlicht 24.09.2015 04:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page ...

  • EPSS 1.12%
  • Veröffentlicht 24.09.2015 04:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensit...

  • EPSS 3.15%
  • Veröffentlicht 24.09.2015 04:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.

  • EPSS 1.1%
  • Veröffentlicht 24.09.2015 04:59:13
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction betwe...