Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 16.0 on Android assigns chrome privileges to Reader Mode pages, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site.

  • EPSS 3.99%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 might allow user-assisted remote attackers to execute arbitrary code v...

  • EPSS 0.85%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 16.0, Thunderbird before 16.0, and SeaMonkey before 2.13 do not properly perform a cast of an unspecified variable during use of the instanceof operator on a JavaScript object, which allows remote attackers to execute arbitrary...

  • EPSS 6.07%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Use-after-free vulnerability in the IME State Manager implementation in Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 allows remote attackers to exe...

  • EPSS 1.42%
  • Veröffentlicht 10.10.2012 17:55:01
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Mozilla Firefox before 16.0, Firefox ESR 10.x before 10.0.8, Thunderbird before 16.0, Thunderbird ESR 10.x before 10.0.8, and SeaMonkey before 2.13 do not properly restrict JSAPI access to the GetProperty function, which allows remote attackers to by...

  • EPSS 13.14%
  • Veröffentlicht 15.09.2012 18:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The TLS protocol 1.2 and earlier, as used in Mozilla Firefox, Google Chrome, Qt, and other products, can encrypt compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plain...

  • EPSS 0.24%
  • Veröffentlicht 15.09.2012 18:55:03
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to...

  • EPSS 4.55%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensit...

  • EPSS 3.05%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 11.04.2025 00:51:21

The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging ...

  • EPSS 0.12%
  • Veröffentlicht 29.08.2012 10:56:41
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse e...