Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Veröffentlicht 22.12.2022 20:15:34
  • Zuletzt bearbeitet 15.04.2025 18:15:43

When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.<br>This bug only affects Firefox for Windows. Other operating systems are unaf...

  • EPSS 0.1%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 19:16:04

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating s...

  • EPSS 0.31%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.

  • EPSS 0.13%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbir...

  • EPSS 0.28%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...

  • EPSS 0.3%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...

  • EPSS 0.19%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 20:15:37

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affect...

  • EPSS 0.86%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 20:15:37

SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript f...

  • EPSS 0.59%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 19:16:03

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

  • EPSS 0.36%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 19:16:03

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability aff...