CVE-2021-4129
- EPSS 0.24%
- Veröffentlicht 22.12.2022 20:15:12
- Zuletzt bearbeitet 16.04.2025 16:15:18
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94. Some of these bugs showed evidence of memory corruption and ...
- EPSS 0.04%
- Veröffentlicht 22.12.2022 20:15:12
- Zuletzt bearbeitet 16.04.2025 16:15:19
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.
CVE-2021-4221
- EPSS 0.49%
- Veröffentlicht 22.12.2022 20:15:12
- Zuletzt bearbeitet 16.04.2025 16:15:19
If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffec...
CVE-2022-0511
- EPSS 0.37%
- Veröffentlicht 22.12.2022 20:15:12
- Zuletzt bearbeitet 16.04.2025 15:15:46
Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96. Some of these bugs showed evidence of memory corru...
CVE-2022-0843
- EPSS 0.21%
- Veröffentlicht 22.12.2022 20:15:12
- Zuletzt bearbeitet 16.04.2025 16:15:19
Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exp...
CVE-2022-1097
- EPSS 0.17%
- Veröffentlicht 22.12.2022 20:15:12
- Zuletzt bearbeitet 16.04.2025 16:15:19
<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Thunderbird < 91.8, Firefox...
CVE-2021-4128
- EPSS 0.29%
- Veröffentlicht 22.12.2022 20:15:11
- Zuletzt bearbeitet 16.04.2025 16:15:18
When transitioning in and out of fullscreen mode, a graphics object was not correctly protected; resulting in memory corruption and a potentially exploitable crash.<br>*This bug only affects Firefox on MacOS. Other operating systems are unaffected.*....
CVE-2022-4066
- EPSS 0.41%
- Veröffentlicht 19.11.2022 19:15:10
- Zuletzt bearbeitet 21.11.2024 07:34:32
A vulnerability was found in davidmoreno onion. It has been rated as problematic. Affected by this issue is the function onion_response_flush of the file src/onion/response.c of the component Log Handler. The manipulation leads to allocation of resou...
CVE-2021-43545
- EPSS 0.47%
- Veröffentlicht 08.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:29:24
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
CVE-2021-43546
- EPSS 0.27%
- Veröffentlicht 08.12.2021 22:15:10
- Zuletzt bearbeitet 21.11.2024 06:29:24
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.