Mozilla

Firefox

2918 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 01.08.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:18

When opening appref-ms files, Firefox did not warn the user that these files may contain malicious code. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 102....

  • EPSS 0.27%
  • Veröffentlicht 01.08.2023 16:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:18

When the number of cookies per domain was exceeded in `document.cookie`, the actual cookie jar sent to the host was no longer consistent with expected cookie jar state. This could have caused requests to be sent with some cookies missing. This vulner...

  • EPSS 0.23%
  • Veröffentlicht 01.08.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:17

Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115....

  • EPSS 7.98%
  • Veröffentlicht 01.08.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:18

In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14...

  • EPSS 0.14%
  • Veröffentlicht 01.08.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:18

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

  • EPSS 0.18%
  • Veröffentlicht 01.08.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:18

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation ...

  • EPSS 0.13%
  • Veröffentlicht 01.08.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 08:34:18

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 11...

  • EPSS 0.25%
  • Veröffentlicht 01.08.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:17

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115...

  • EPSS 0.3%
  • Veröffentlicht 01.08.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:17

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox...

  • EPSS 0.4%
  • Veröffentlicht 01.08.2023 15:15:09
  • Zuletzt bearbeitet 21.11.2024 08:34:17

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.