CVE-2021-29951
- EPSS 0.39%
- Veröffentlicht 24.06.2021 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:02:02
The Mozilla Maintenance Service granted SERVICE_START access to BUILTIN|Users which, in a domain network, grants normal remote users access to start or stop the service. This could be used to prevent the browser update service from operating (if an a...
CVE-2021-29952
- EPSS 0.25%
- Veröffentlicht 24.06.2021 14:15:09
- Zuletzt bearbeitet 21.11.2024 06:02:02
When Web Render components were destructed, a race condition could have caused undefined behavior, and we presume that with enough effort may have been exploitable to run arbitrary code. This vulnerability affects Firefox < 88.0.1 and Firefox for And...
CVE-2021-30547
- EPSS 3.19%
- Veröffentlicht 15.06.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:04:09
Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
CVE-2011-3656
- EPSS 0.27%
- Veröffentlicht 02.06.2021 17:15:07
- Zuletzt bearbeitet 21.11.2024 01:30:56
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.
CVE-2007-5967
- EPSS 0.11%
- Veröffentlicht 17.05.2021 12:15:07
- Zuletzt bearbeitet 21.11.2024 00:39:03
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
CVE-2021-23982
- EPSS 0.2%
- Veröffentlicht 31.03.2021 14:15:19
- Zuletzt bearbeitet 21.11.2024 05:52:09
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox E...
CVE-2021-23983
- EPSS 0.37%
- Veröffentlicht 31.03.2021 14:15:19
- Zuletzt bearbeitet 21.11.2024 05:52:09
By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.
CVE-2021-23984
- EPSS 0.27%
- Veröffentlicht 31.03.2021 14:15:19
- Zuletzt bearbeitet 21.11.2024 05:52:09
A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to tric...
CVE-2021-23985
- EPSS 0.51%
- Veröffentlicht 31.03.2021 14:15:19
- Zuletzt bearbeitet 21.11.2024 05:52:09
If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user. This would have allowed a remo...
CVE-2021-23986
- EPSS 0.05%
- Veröffentlicht 31.03.2021 14:15:19
- Zuletzt bearbeitet 21.11.2024 05:52:09
A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy by...