Mozilla

Firefox

2920 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.52%
  • Veröffentlicht 07.01.2021 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:20:36

The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free ...

  • EPSS 0.25%
  • Veröffentlicht 07.01.2021 14:15:11
  • Zuletzt bearbeitet 21.11.2024 05:20:36

Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

  • EPSS 0.18%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:34

OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are...

  • EPSS 0.35%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:34

Firefox did not block execution of scripts with incorrect MIME types when the response was intercepted and cached through a ServiceWorker. This could lead to a cross-site script inclusion vulnerability, or a Content Security Policy bypass. This vulne...

  • EPSS 0.5%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:34

During browser shutdown, reference decrementing could have occured on a previously freed object, resulting in a use-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and T...

  • EPSS 0.67%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:34

If the Compact() method was called on an nsTArray, the array could have been reallocated without updating other pointers, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Th...

  • EPSS 0.28%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:35

When DNS over HTTPS is in use, it intentionally filters RFC1918 and related IP ranges from the responses as these do not make sense coming from a DoH resolver. However when an IPv4 address was mapped through IPv6, these addresses were erroneously let...

  • EPSS 0.22%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:35

Cross-origin iframes that contained a login form could have been recognized by the login autofill service, and populated. This could have been used in clickjacking attacks, as well as be read across partitions in dynamic first party isolation. This v...

  • EPSS 0.41%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:35

Repeated calls to the history and location interfaces could have been used to hang the browser. This was addressed by introducing rate-limiting to these API calls. This vulnerability affects Firefox < 83.

  • EPSS 0.3%
  • Veröffentlicht 09.12.2020 01:15:13
  • Zuletzt bearbeitet 21.11.2024 05:20:35

If the Remote Debugging via USB feature was enabled in Firefox for Android on an Android version prior to Android 6.0, untrusted apps could have connected to the feature and operated with the privileges of the browser to read and interact with web co...