Mozilla

Firefox ESR

652 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.25%
  • Veröffentlicht 21.11.2023 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:21

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thu...

  • EPSS 0.39%
  • Veröffentlicht 21.11.2023 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:21

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

  • EPSS 0.41%
  • Veröffentlicht 21.11.2023 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:22

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about t...

  • EPSS 0.43%
  • Veröffentlicht 21.11.2023 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:22

Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

  • EPSS 0.43%
  • Veröffentlicht 21.11.2023 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:22

When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerabilit...

  • EPSS 0.36%
  • Veröffentlicht 21.11.2023 15:15:07
  • Zuletzt bearbeitet 21.11.2024 08:43:22

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox ...

  • EPSS 0.83%
  • Veröffentlicht 25.10.2023 18:17:44
  • Zuletzt bearbeitet 21.11.2024 08:42:21

Drivers are not always robust to extremely large draw calls and in some cases this scenario could have led to a crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • EPSS 0.42%
  • Veröffentlicht 25.10.2023 18:17:44
  • Zuletzt bearbeitet 21.11.2024 08:42:21

A malicious installed WebExtension could open arbitrary URLs, which under the right circumstance could be leveraged to collect sensitive user data. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

  • EPSS 0.17%
  • Veröffentlicht 25.10.2023 18:17:44
  • Zuletzt bearbeitet 21.11.2024 08:42:22

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. *Note: This issue only affected macOS operating systems. Other operating systems are unaff...

  • EPSS 0.21%
  • Veröffentlicht 25.10.2023 18:17:44
  • Zuletzt bearbeitet 21.11.2024 08:42:22

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are una...