CVE-2021-23977
- EPSS 0.37%
- Veröffentlicht 26.02.2021 03:15:14
- Zuletzt bearbeitet 21.11.2024 05:52:08
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories. Note: This issue is only affected Firefox for Android. Other operating systems are u...
CVE-2021-23953
- EPSS 0.38%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:05
If a user clicked into a specifically crafted PDF, the PDF reader could be confused into leaking cross-origin information, when said information is served as chunked data. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR <...
CVE-2021-23954
- EPSS 0.25%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:05
Using the new logical assignment operators in a JavaScript switch statement could have caused a type confusion, leading to a memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firef...
CVE-2021-23955
- EPSS 0.14%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:05
The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85.
CVE-2021-23956
- EPSS 0.18%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt. This vulnerability affects Firefox < 85.
CVE-2021-23957
- EPSS 0.28%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.
CVE-2021-23958
- EPSS 0.32%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85.
CVE-2021-23959
- EPSS 0.3%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Fir...
CVE-2021-23960
- EPSS 0.3%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
Performing garbage collection on re-declared JavaScript variables resulted in a user-after-poison, and a potentially exploitable crash. This vulnerability affects Firefox < 85, Thunderbird < 78.7, and Firefox ESR < 78.7.
CVE-2021-23961
- EPSS 0.63%
- Veröffentlicht 26.02.2021 03:15:13
- Zuletzt bearbeitet 21.11.2024 05:52:06
Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.