Mozilla

Firefox ESR

640 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 19.06.2023 11:15:09
  • Zuletzt bearbeitet 11.12.2024 16:15:09

Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Ot...

  • EPSS 1.07%
  • Veröffentlicht 19.06.2023 10:15:09
  • Zuletzt bearbeitet 11.12.2024 16:15:08

An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This ...

  • EPSS 0.07%
  • Veröffentlicht 19.06.2023 10:15:09
  • Zuletzt bearbeitet 11.12.2024 16:15:08

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because t...

  • EPSS 0.23%
  • Veröffentlicht 19.06.2023 10:15:09
  • Zuletzt bearbeitet 21.11.2024 08:02:54

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11,...

  • EPSS 0.14%
  • Veröffentlicht 02.06.2023 17:15:13
  • Zuletzt bearbeitet 21.11.2024 08:02:53

In multiple cases browser prompts could have been obscured by popups controlled by content. These could have led to potential user confusion and spoofing attacks. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.1...

  • EPSS 0.15%
  • Veröffentlicht 02.06.2023 17:15:13
  • Zuletzt bearbeitet 21.11.2024 08:02:54

An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • EPSS 0.19%
  • Veröffentlicht 02.06.2023 17:15:13
  • Zuletzt bearbeitet 31.01.2025 16:15:29

A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • EPSS 0.15%
  • Veröffentlicht 02.06.2023 17:15:13
  • Zuletzt bearbeitet 21.11.2024 08:02:54

A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • EPSS 0.14%
  • Veröffentlicht 02.06.2023 17:15:13
  • Zuletzt bearbeitet 27.05.2025 17:15:24

An attacker could have positioned a `datalist` element to obscure the address bar. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • EPSS 0.18%
  • Veröffentlicht 02.06.2023 17:15:13
  • Zuletzt bearbeitet 21.11.2024 08:02:54

When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.