Mozilla

Firefox

2939 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.7%
  • Veröffentlicht 24.09.2015 04:59:11
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0, when reader mode is enabled, allows remote attackers to spoof the relationship between address-bar URLs and web content via a crafted web site.

  • EPSS 1.2%
  • Veröffentlicht 24.09.2015 04:59:10
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbi...

  • EPSS 7.97%
  • Veröffentlicht 24.09.2015 04:59:09
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.

  • EPSS 0.11%
  • Veröffentlicht 24.09.2015 04:59:08
  • Zuletzt bearbeitet 12.04.2025 10:46:40

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.

  • EPSS 2.1%
  • Veröffentlicht 24.09.2015 04:59:07
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 pro...

  • EPSS 0.58%
  • Veröffentlicht 24.09.2015 04:59:06
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The TCP Socket API implementation in Mozilla Firefox before 41.0 mishandles array boundaries that were established with a navigator.mozTCPSocket.open method call and send method calls, which allows remote TCP servers to obtain sensitive information f...

  • EPSS 0.78%
  • Veröffentlicht 24.09.2015 04:59:04
  • Zuletzt bearbeitet 12.04.2025 10:46:40

js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.

  • EPSS 2.92%
  • Veröffentlicht 24.09.2015 04:59:03
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

  • EPSS 3.17%
  • Veröffentlicht 24.09.2015 04:59:02
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary cod...

  • EPSS 0.48%
  • Veröffentlicht 24.09.2015 04:59:00
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.