Mozilla

Firefox ESR

866 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.44%
  • Published 09.12.2020 01:15:13
  • Last modified 21.11.2024 05:20:35

Some websites have a feature "Show Password" where clicking a button will change a password field into a textbook field, revealing the typed password. If, when using a software keyboard that remembers user input, a user typed their password and used ...

  • EPSS 0.44%
  • Published 09.12.2020 01:15:13
  • Last modified 21.11.2024 05:20:35

Searching for a single word from the address bar caused an mDNS request to be sent on the local network searching for a hostname consisting of that string; resulting in an information leak. *Note: This issue only affected Windows operating systems. O...

  • EPSS 0.64%
  • Published 09.12.2020 01:15:13
  • Last modified 21.11.2024 05:20:35

Mozilla developers reported memory safety bugs present in Firefox 82 and Firefox ESR 78.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. T...

Exploit
  • EPSS 76.01%
  • Published 09.12.2020 01:15:12
  • Last modified 21.11.2024 05:20:33

In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thunderbird < 78.4.2.

  • EPSS 0.19%
  • Published 09.12.2020 01:15:12
  • Last modified 21.11.2024 05:20:33

A parsing and event loading mismatch in Firefox's SVG code could have allowed load events to fire, even after sanitization. An attacker already capable of exploiting an XSS vulnerability in privileged internal pages could have used this attack to byp...

  • EPSS 0.28%
  • Published 09.12.2020 01:15:12
  • Last modified 21.11.2024 05:20:34

It was possible to cause the browser to enter fullscreen mode without displaying the security UI; thus making it possible to attempt a phishing attack or otherwise confuse the user. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thu...

  • EPSS 0.53%
  • Published 09.12.2020 01:15:12
  • Last modified 21.11.2024 05:20:34

In some cases, removing HTML elements during sanitization would keep existing SVG event handlers and therefore lead to XSS. This vulnerability affects Firefox < 83, Firefox ESR < 78.5, and Thunderbird < 78.5.

  • EPSS 1.57%
  • Published 22.10.2020 21:15:13
  • Last modified 21.11.2024 05:06:00

Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to...

  • EPSS 0.37%
  • Published 01.10.2020 19:15:13
  • Last modified 21.11.2024 05:05:58

By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to install an extension. Combined with user confusion, this ...

  • EPSS 0.45%
  • Published 01.10.2020 19:15:13
  • Last modified 21.11.2024 05:05:58

When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could have been exploited to run arbitrary code. This vu...