Mozilla

Firefox ESR

866 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.03%
  • Veröffentlicht 11.06.2018 21:29:15
  • Zuletzt bearbeitet 21.11.2024 04:08:15

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or ...

  • EPSS 0.54%
  • Veröffentlicht 11.06.2018 21:29:15
  • Zuletzt bearbeitet 21.11.2024 04:08:16

In the Windows 10 April 2018 Update, Windows Defender SmartScreen honors the "SEE_MASK_FLAG_NO_UI" flag associated with downloaded files and will not show any UI. Files that are unknown and potentially dangerous will be allowed to run because SmartSc...

  • EPSS 2.44%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:10

A lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can potentially allow for sandbox escape through memory corruption in the parent process. This vulnerability affects Thunde...

  • EPSS 1.22%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:10

When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

  • EPSS 1.48%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:10

Under certain circumstances the "fetch()" API can return transient local copies of resources that were sent with a "no-store" or "no-cache" cache header instead of downloading a copy from the network as it should. This can result in previously stored...

  • EPSS 5.99%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:12

An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

  • EPSS 4.12%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:12

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 an...

  • EPSS 29.45%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:12

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

  • EPSS 1.5%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:12

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

  • EPSS 1.68%
  • Veröffentlicht 11.06.2018 21:29:14
  • Zuletzt bearbeitet 21.11.2024 04:08:12

A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52....