Mozilla

Firefox

3041 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 3.21%
  • Veröffentlicht 24.09.2015 04:59:23
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The XULContentSinkImpl::AddText function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via...

  • EPSS 3.21%
  • Veröffentlicht 24.09.2015 04:59:22
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The nsAttrAndChildArray::GrowBy function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via...

  • EPSS 3.21%
  • Veröffentlicht 24.09.2015 04:59:21
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The nsUnicodeToUTF8::GetMaxLength function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact v...

  • EPSS 3.21%
  • Veröffentlicht 24.09.2015 04:59:20
  • Zuletzt bearbeitet 12.04.2025 10:46:40

The ConvertDialogOptions function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknow...

  • EPSS 0.59%
  • Veröffentlicht 24.09.2015 04:59:19
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to bypass CORS preflight protection mechanisms by leveraging (1) duplicate cache-key generation or (2) retrieval of a value from an incorrect HTTP Access-Control-* re...

  • EPSS 0.44%
  • Veröffentlicht 24.09.2015 04:59:18
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an...

  • EPSS 3.21%
  • Veröffentlicht 24.09.2015 04:59:17
  • Zuletzt bearbeitet 12.04.2025 10:46:40

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

  • EPSS 1.35%
  • Veröffentlicht 24.09.2015 04:59:16
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page ...

  • EPSS 2.01%
  • Veröffentlicht 24.09.2015 04:59:15
  • Zuletzt bearbeitet 12.04.2025 10:46:40

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensit...

  • EPSS 3.96%
  • Veröffentlicht 24.09.2015 04:59:14
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.