Mozilla

Firefox ESR

866 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Published 06.08.2024 13:15:57
  • Last modified 12.08.2024 16:04:20

Insufficient checks when processing graphics shared memory could have led to memory corruption. This could be leveraged by an attacker to perform a sandbox escape. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, T...

  • EPSS 0.32%
  • Published 06.08.2024 13:15:57
  • Last modified 24.03.2025 17:15:19

A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

  • EPSS 0.18%
  • Published 06.08.2024 13:15:57
  • Last modified 12.08.2024 16:05:10

Incomplete WebAssembly exception handing could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • EPSS 0.18%
  • Published 06.08.2024 13:15:57
  • Last modified 12.08.2024 16:06:05

Editor code failed to check an attribute value. This could have led to an out-of-bounds read. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • EPSS 0.14%
  • Published 06.08.2024 13:15:57
  • Last modified 25.03.2025 17:16:12

Firefox adds web-compatibility shims in place of some tracking scripts blocked by Enhanced Tracking Protection. On a site protected by Content Security Policy in "strict-dynamic" mode, an attacker able to inject an HTML element could have used a DOM...

  • EPSS 0.1%
  • Published 06.08.2024 13:15:57
  • Last modified 12.08.2024 16:07:19

It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 12...

  • EPSS 0.2%
  • Published 06.08.2024 13:15:57
  • Last modified 17.09.2024 19:15:28

ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128....

  • EPSS 0.16%
  • Published 06.08.2024 13:15:57
  • Last modified 18.03.2025 19:15:47

Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • EPSS 0.18%
  • Published 06.08.2024 13:15:57
  • Last modified 12.08.2024 16:10:00

Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

  • EPSS 0.11%
  • Published 06.08.2024 13:15:57
  • Last modified 12.08.2024 16:09:09

The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and ...