VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2023-4573MedSep 11, 2023
    risk 0.42cvss 6.5epss 0.01

    When receiving rendering data over IPC `mStream` could have been destroyed when initialized, which could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird <…

  • CVE-2023-4053MedAug 1, 2023
    risk 0.42cvss 6.5epss 0.01

    A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and…

  • CVE-2023-4052MedAug 1, 2023
    risk 0.42cvss 6.5epss 0.01

    The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of…

  • CVE-2023-37456MedJul 12, 2023
    risk 0.42cvss 6.5epss 0.00

    The session restore helper crashed whenever there was no parameter sent to the message handler. This vulnerability affects Firefox for iOS < 115.

  • CVE-2023-3482MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    When Firefox is configured to block storage of all cookies, it was still possible to store data in localstorage by using an iframe with a source of 'about:blank'. This could have led to malicious websites storing tracking data without permission. This vulnerability affects…

  • CVE-2023-37210MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.00

    A website could prevent a user from exiting full-screen mode via alert and prompt calls. This could lead to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.

  • CVE-2023-37206MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    Uploading files which contain symlinks may have allowed an attacker to trick a user into submitting sensitive data to a malicious website. This vulnerability affects Firefox < 115.

  • CVE-2023-37205MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    The use of RTL Arabic characters in the address bar may have allowed for URL spoofing. This vulnerability affects Firefox < 115.

  • CVE-2023-37204MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.

  • CVE-2023-37207MedJul 5, 2023
    risk 0.42cvss 6.5epss 0.01

    A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and…

  • CVE-2023-29545MedJun 19, 2023
    risk 0.42cvss 6.5epss 0.01

    Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox…

  • CVE-2023-32210MedJun 19, 2023
    risk 0.42cvss 6.5epss 0.01

    Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. This…

  • CVE-2023-32211MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A type checking bug would have led to invalid code being compiled. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • CVE-2023-32206MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    An out-of-bound read could have led to a crash in the RLBox Expat driver. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

  • CVE-2023-29549MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Under certain circumstances, a call to the bind function may have resulted in the incorrect realm. This may have created a vulnerability relating to JavaScript-implemented sandboxes such as SES. This vulnerability affects Firefox for Android < 112, Firefox < 112,…

  • CVE-2023-29548MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A wrong lowering instruction in the ARM64 Ion compiler resulted in a wrong optimization result. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

  • CVE-2023-29547MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    When a secure cookie existed in the Firefox cookie jar an insecure cookie for the same domain could have been created, when it should have silently failed. This could have led to a desynchronization in expected results when reading from the secure cookie. This vulnerability…

  • CVE-2023-29544MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    If multiple instances of resource exhaustion occurred at the incorrect time, the garbage collector could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

  • CVE-2023-29535MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox…

  • CVE-2023-28164MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Dragging a URL from a cross-origin iframe that was removed during the drag could have led to user confusion and website spoofing attacks. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

Page 71 of 168