Mozilla

Firefox ESR

755 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.77%
  • Veröffentlicht 19.03.2024 12:15:09
  • Zuletzt bearbeitet 17.07.2025 13:35:05

If an attacker could find a way to trigger a particular code path in `SafeRefPtr`, it could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird <...

  • EPSS 0.32%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:10:55

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firef...

Exploit
  • EPSS 1.45%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:15:20

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9,...

Exploit
  • EPSS 0.19%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:18:20

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Fir...

Exploit
  • EPSS 1.03%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:19:51

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

Exploit
  • EPSS 0.29%
  • Veröffentlicht 19.03.2024 12:15:08
  • Zuletzt bearbeitet 01.04.2025 17:37:13

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • EPSS 0.25%
  • Veröffentlicht 19.03.2024 12:15:07
  • Zuletzt bearbeitet 04.11.2025 19:16:23

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • EPSS 0.5%
  • Veröffentlicht 20.02.2024 14:15:08
  • Zuletzt bearbeitet 27.03.2025 14:35:06

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

  • EPSS 0.38%
  • Veröffentlicht 20.02.2024 14:15:08
  • Zuletzt bearbeitet 27.03.2025 14:36:57

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < ...

  • EPSS 0.34%
  • Veröffentlicht 20.02.2024 14:15:08
  • Zuletzt bearbeitet 27.03.2025 14:37:40

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123, Firefox ESR < 115.8...