Mozilla

Firefox

3462 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.11%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:15:20

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9,...

Exploit
  • EPSS 0.39%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:18:20

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Fir...

Exploit
  • EPSS 0.6%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:19:51

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

Exploit
  • EPSS 0.7%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:37:13

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • EPSS 0.82%
  • Veröffentlicht 19.03.2024 12:15:07
  • Zuletzt bearbeitet 04.11.2025 19:16:23

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • EPSS 0.31%
  • Veröffentlicht 22.02.2024 15:15:08
  • Zuletzt bearbeitet 27.03.2025 14:45:24

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.

  • EPSS 0.34%
  • Veröffentlicht 22.02.2024 15:15:08
  • Zuletzt bearbeitet 27.03.2025 14:46:21

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.

  • EPSS 0.28%
  • Veröffentlicht 22.02.2024 15:15:08
  • Zuletzt bearbeitet 27.03.2025 14:46:58

An attacker could have executed unauthorized scripts on top origin sites using a JavaScript URI when opening an external URL with a custom Firefox scheme. This vulnerability affects Firefox for iOS < 123.

  • EPSS 0.48%
  • Veröffentlicht 20.02.2024 14:15:09
  • Zuletzt bearbeitet 27.03.2025 14:39:50

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

  • EPSS 0.47%
  • Veröffentlicht 20.02.2024 14:15:09
  • Zuletzt bearbeitet 27.03.2025 14:40:12

The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox ...