Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.56%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the nsIDocument::GetRootElement function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary co...

  • EPSS 1.77%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the mozilla::ResetDir function in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to execute arbitrary code or caus...

  • EPSS 1.91%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The System Only Wrapper (SOW) and Chrome Object Wrapper (COW) implementations in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly restrict XBL user-defined ...

  • EPSS 1.2%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site.

Warnung
  • EPSS 49.62%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 22.10.2025 01:15:48

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause...

  • EPSS 0.73%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to ...

  • EPSS 0.44%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy a...

  • EPSS 2.11%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly handle the lack of a wrapper, which allows remote attackers to caus...

  • EPSS 0.16%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME el...

  • EPSS 0.43%
  • Veröffentlicht 26.06.2013 03:19:10
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.