VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2024-10464MedOct 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and…

  • CVE-2024-10463MedOct 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

  • CVE-2024-10462MedOct 29, 2024
    risk 0.42cvss 6.5epss 0.01

    Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

  • CVE-2024-9936MedOct 14, 2024
    risk 0.42cvss 6.5epss 0.00

    When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.

  • CVE-2024-9391MedOct 1, 2024
    risk 0.42cvss 6.5epss 0.00

    A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of…

  • CVE-2024-7531MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.00

    Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher…

  • CVE-2024-7529MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.01

    The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • CVE-2024-7526MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.01

    ANGLE failed to initialize parameters which lead to reading from uninitialized memory. This could be leveraged to leak sensitive data from memory. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.

  • CVE-2024-7518MedAug 6, 2024
    risk 0.42cvss 6.5epss 0.01

    Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

  • CVE-2024-38312MedJun 13, 2024
    risk 0.42cvss 6.5epss 0.00

    When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.

  • CVE-2024-5692MedJun 11, 2024
    risk 0.42cvss 6.5epss 0.01

    On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other…

  • CVE-2024-4774MedMay 14, 2024
    risk 0.42cvss 6.5epss 0.00

    The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.

  • CVE-2024-3855MedApr 16, 2024
    risk 0.42cvss 6.5epss 0.00

    In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

  • CVE-2023-5388MedMar 19, 2024
    risk 0.42cvss 6.5epss 0.01

    NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

  • CVE-2024-1556MedFeb 20, 2024
    risk 0.42cvss 6.5epss 0.00

    The incorrect object was checked for NULL in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 123.

  • CVE-2024-1547MedFeb 20, 2024
    risk 0.42cvss 6.5epss 0.01

    Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

  • CVE-2024-0754MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.00

    Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

  • CVE-2024-0753MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.01

    In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

  • CVE-2024-0752MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.00

    A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.

  • CVE-2024-0747MedJan 23, 2024
    risk 0.42cvss 6.5epss 0.01

    When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

Page 69 of 168