VYPR

Firefox

by Mozilla Corporation

Source repositories

CVEs (3,344)

  • CVE-2023-28163MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When downloading files through the Save As dialog on Windows with suggested filenames containing environment variable names, Windows would have resolved those in the context of the current user. *This bug only affects Firefox on Windows. Other versions of Firefox are…

  • CVE-2023-28160MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When following a redirect to a publicly accessible web extension file, the URL may have been translated to the actual local path, leaking potentially sensitive information. This vulnerability affects Firefox < 111.

  • CVE-2023-25752MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When accessing throttled streams, the count of available bytes needed to be checked in the calling function to be within bounds. This may have lead future code to be incorrect and vulnerable. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

  • CVE-2023-25751MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly. This could lead to a potentially exploitable crash. This vulnerability affects Firefox < 111, Firefox ESR < 102.9, and Thunderbird < 102.9.

  • CVE-2023-25742MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

  • CVE-2023-25741MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects…

  • CVE-2023-25738MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Members of the DEVMODEW struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.*This bug only affects Firefox on…

  • CVE-2023-25728MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    The Content-Security-Policy-Report-Only header could allow an attacker to leak a child iframe's unredacted URI when interaction with that iframe triggers a redirect. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

  • CVE-2023-23604MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    A duplicate `SystemPrincipal` object could be created when parsing a non-system html document via `DOMParser::ParseFromSafeString`. This could have lead to bypassing web security checks. This vulnerability affects Firefox < 109.

  • CVE-2023-23603MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR <…

  • CVE-2023-23602MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7,…

  • CVE-2023-23601MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

  • CVE-2023-23600MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for…

  • CVE-2023-23599MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

  • CVE-2023-23598MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR <…

  • CVE-2023-23597MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.00

    A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This…

  • CVE-2023-1945MedJun 2, 2023
    risk 0.42cvss 6.5epss 0.01

    Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 102.10 and Firefox ESR < 102.10.

  • CVE-2022-46880MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    A missing check related to tex units could have led to a use-after-free and potentially exploitable crash.*Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue. The fix was included in the original release of Firefox 105.…

  • CVE-2022-46875MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. *Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108,…

  • CVE-2022-45420MedDec 22, 2022
    risk 0.42cvss 6.5epss 0.01

    Use tables inside of an iframe, an attacker could have caused iframe contents to be rendered outside the boundaries of the iframe, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

Page 72 of 168