Mozilla

Firefox

2867 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 24.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:02:01

Lack of escaping allowed HTML injection when a webpage was viewed in Reader View. While a Content Security Policy prevents direct code execution, HTML injection is still possible. *Note: This issue only affected Firefox for Android. Other operating s...

  • EPSS 0.45%
  • Veröffentlicht 24.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:02:02

The WebAssembly JIT could miscalculate the size of a return type, which could lead to a null read and result in a crash. *Note: This issue only affected x86-32 platforms. Other platforms are unaffected.*. This vulnerability affects Firefox ESR < 78.1...

  • EPSS 0.24%
  • Veröffentlicht 24.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:02:02

Ports that were written as an integer overflow above the bounds of a 16-bit integer could have bypassed port blocking restrictions when used in the Alt-Svc header. This vulnerability affects Firefox ESR < 78.10, Thunderbird < 78.10, and Firefox < 88.

  • EPSS 0.35%
  • Veröffentlicht 24.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:02:02

Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. ...

  • EPSS 0.39%
  • Veröffentlicht 24.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:02:02

The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an a...

  • EPSS 0.25%
  • Veröffentlicht 24.06.2021 14:15:09
  • Zuletzt bearbeitet 21.11.2024 06:02:02

When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for And...

  • EPSS 0.97%
  • Veröffentlicht 15.06.2021 22:15:08
  • Zuletzt bearbeitet 21.11.2024 06:04:09

Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • EPSS 0.27%
  • Veröffentlicht 02.06.2021 17:15:07
  • Zuletzt bearbeitet 21.11.2024 01:30:56

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

  • EPSS 0.11%
  • Veröffentlicht 17.05.2021 12:15:07
  • Zuletzt bearbeitet 21.11.2024 00:39:03

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

  • EPSS 0.2%
  • Veröffentlicht 31.03.2021 14:15:19
  • Zuletzt bearbeitet 21.11.2024 05:52:09

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox E...