Mozilla

Firefox

2939 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 22.12.2022 20:15:41
  • Zuletzt bearbeitet 15.04.2025 16:15:20

Service Workers should not be able to infer information about opaque cross-origin responses; but timing information for cross-origin media combined with Range requests might have allowed them to determine the presence or length of a media file. This ...

  • EPSS 0.15%
  • Veröffentlicht 22.12.2022 20:15:41
  • Zuletzt bearbeitet 15.04.2025 16:15:20

Through a series of popup and <code>window.print()</code> calls, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Fi...

  • EPSS 0.15%
  • Veröffentlicht 22.12.2022 20:15:41
  • Zuletzt bearbeitet 15.04.2025 16:15:21

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread than creation could have led to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

  • EPSS 0.14%
  • Veröffentlicht 22.12.2022 20:15:40
  • Zuletzt bearbeitet 15.04.2025 16:15:19

A same-origin policy violation could have allowed the theft of cross-origin URL entries, leaking the result of a redirect, via `performance.getEntries()`. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and Thunderbird < 102.4.

  • EPSS 0.19%
  • Veröffentlicht 22.12.2022 20:15:40
  • Zuletzt bearbeitet 15.04.2025 16:15:19

Certain types of allocations were missing annotations that, if the Garbage Collector was in a specific state, could have lead to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 106, Firefox ESR < 102.4, and...

  • EPSS 0.2%
  • Veröffentlicht 22.12.2022 20:15:40
  • Zuletzt bearbeitet 15.04.2025 16:15:19

If a website called `window.print()` in a particular way, it could cause a denial of service of the browser, which may persist beyond browser restart depending on the user's session restore settings. This vulnerability affects Firefox < 106, Firefox ...

  • EPSS 0.28%
  • Veröffentlicht 22.12.2022 20:15:40
  • Zuletzt bearbeitet 15.04.2025 16:15:20

If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the `ThirdPartyUtil` component. This vulnerability affects Firefox < 106.

  • EPSS 0.37%
  • Veröffentlicht 22.12.2022 20:15:39
  • Zuletzt bearbeitet 15.04.2025 15:15:59

By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite cookies from a secure context, leading to session fixation and other attacks. This vulnerability affec...

  • EPSS 0.13%
  • Veröffentlicht 22.12.2022 20:15:39
  • Zuletzt bearbeitet 15.04.2025 15:15:59

During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into untrusted subdocuments. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefo...

  • EPSS 0.16%
  • Veröffentlicht 22.12.2022 20:15:39
  • Zuletzt bearbeitet 15.04.2025 15:15:59

Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.