Mozilla

Firefox

2939 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.15%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 19:16:04

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating s...

  • EPSS 0.38%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.

  • EPSS 0.24%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was too large for the container. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbir...

  • EPSS 0.39%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...

  • EPSS 0.52%
  • Veröffentlicht 22.12.2022 20:15:33
  • Zuletzt bearbeitet 15.04.2025 18:15:42

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While...

  • EPSS 0.24%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 20:15:37

Even when an iframe was sandboxed with <code>allow-top-navigation-by-user-activation</code>, if it received a redirect header to an external protocol the browser would process the redirect and prompt the user as appropriate. This vulnerability affect...

  • EPSS 0.53%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 20:15:37

SVG <code><use></code> tags that referenced a same-origin document could have resulted in script execution if attacker input was sanitized via the HTML Sanitizer API. This would have required the attacker to reference a same-origin JavaScript f...

  • EPSS 0.59%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 19:16:03

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

  • EPSS 0.35%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 19:16:03

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability aff...

  • EPSS 0.16%
  • Veröffentlicht 22.12.2022 20:15:32
  • Zuletzt bearbeitet 15.04.2025 19:16:03

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wi...