CVE-2023-6205
- EPSS 0.41%
- Veröffentlicht 21.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:21
It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6206
- EPSS 0.43%
- Veröffentlicht 21.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:22
The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about t...
CVE-2023-6207
- EPSS 0.46%
- Veröffentlicht 21.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:22
Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.
CVE-2023-6208
- EPSS 0.46%
- Veröffentlicht 21.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:22
When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerabilit...
CVE-2023-6209
- EPSS 0.38%
- Veröffentlicht 21.11.2023 15:15:07
- Zuletzt bearbeitet 21.11.2024 08:43:22
Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox ...
CVE-2023-5758
- EPSS 0.3%
- Veröffentlicht 25.10.2023 18:17:45
- Zuletzt bearbeitet 12.06.2025 15:15:34
When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.
CVE-2023-5722
- EPSS 0.22%
- Veröffentlicht 25.10.2023 18:17:44
- Zuletzt bearbeitet 21.11.2024 08:42:21
Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a server-supplied Vary header. This vulnerability affects Firefox < 119.
CVE-2023-5723
- EPSS 0.21%
- Veröffentlicht 25.10.2023 18:17:44
- Zuletzt bearbeitet 21.11.2024 08:42:21
An attacker with temporary script access to a site could have set a cookie containing invalid characters using `document.cookie` that could have led to unknown errors. This vulnerability affects Firefox < 119.
CVE-2023-5724
- EPSS 0.77%
- Veröffentlicht 25.10.2023 18:17:44
- Zuletzt bearbeitet 21.11.2024 08:42:21
Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.
CVE-2023-5725
- EPSS 0.38%
- Veröffentlicht 25.10.2023 18:17:44
- Zuletzt bearbeitet 21.11.2024 08:42:21
A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.