Mozilla

Firefox

3102 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.74%
  • Veröffentlicht 16.12.2015 11:59:21
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.

  • EPSS 3.35%
  • Veröffentlicht 16.12.2015 11:59:20
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory all...

  • EPSS 1.48%
  • Veröffentlicht 16.12.2015 11:59:19
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.

  • EPSS 1.48%
  • Veröffentlicht 16.12.2015 11:59:18
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.

  • EPSS 1.26%
  • Veröffentlicht 16.12.2015 11:59:17
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length misc...

  • EPSS 1.26%
  • Veröffentlicht 16.12.2015 11:59:16
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.

  • EPSS 1.3%
  • Veröffentlicht 16.12.2015 11:59:15
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.

  • EPSS 0.89%
  • Veröffentlicht 16.12.2015 11:59:14
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 ...

  • EPSS 0.44%
  • Veröffentlicht 16.12.2015 11:59:13
  • Zuletzt bearbeitet 06.05.2026 22:30:45

The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an ...

  • EPSS 15.48%
  • Veröffentlicht 16.12.2015 11:59:12
  • Zuletzt bearbeitet 06.05.2026 22:30:45

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.