Количество 15 501
Количество 15 501
GHSA-7f3m-mqm5-5x2c
If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140.
GHSA-7cgj-mr4w-j8w6
This vulnerability affects Firefox < 143.0.3.
GHSA-7c9h-gj9v-x83c
A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.
GHSA-79x3-rj66-524h
Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.
GHSA-79f9-29qm-cx67
A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.
GHSA-7926-phm6-wvh3
Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.
GHSA-78p9-f5p7-3p6q
The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."
GHSA-78mc-5g34-3h4m
Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.
GHSA-78h7-72xw-23vg
The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.
GHSA-7873-qcmm-76jc
In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.
GHSA-77wh-39r6-7gg9
A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction. This could be used to open new tabs in a denial of service (DOS) attack or to display unwanted content from arbitrary URLs to users. This vulnerability affects Firefox < 59.
GHSA-77q8-crvw-8w9q
When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.
GHSA-77mp-cm2p-44gj
When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.
GHSA-7785-cqjm-vp4q
When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66.
GHSA-764w-vr4w-hf3x
Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 76.
GHSA-75p5-w5j4-v8qj
Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145.
GHSA-7526-6xhc-xh2w
During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.
GHSA-748v-pxm5-9m8q
Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.
GHSA-73hr-36wp-4xmc
Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.
GHSA-737f-pfm5-cmq6
If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the <code>ThirdPartyUtil</code> component. This vulnerability affects Firefox < 106.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-7f3m-mqm5-5x2c If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-7cgj-mr4w-j8w6 This vulnerability affects Firefox < 143.0.3. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-7c9h-gj9v-x83c A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval. | 0% Низкий | почти 4 года назад | ||
GHSA-79x3-rj66-524h Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property. | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
GHSA-79f9-29qm-cx67 A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58. | CVSS3: 7.5 | 35% Средний | больше 3 лет назад | |
GHSA-7926-phm6-wvh3 Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92. | 0% Низкий | больше 3 лет назад | ||
GHSA-78p9-f5p7-3p6q The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop." | 12% Средний | почти 4 года назад | ||
GHSA-78mc-5g34-3h4m Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code. | 4% Низкий | больше 3 лет назад | ||
GHSA-78h7-72xw-23vg The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment. | 2% Низкий | больше 3 лет назад | ||
GHSA-7873-qcmm-76jc In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-77wh-39r6-7gg9 A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction. This could be used to open new tabs in a denial of service (DOS) attack or to display unwanted content from arbitrary URLs to users. This vulnerability affects Firefox < 59. | CVSS3: 8.2 | 1% Низкий | больше 3 лет назад | |
GHSA-77q8-crvw-8w9q When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84. | 2% Низкий | больше 3 лет назад | ||
GHSA-77mp-cm2p-44gj When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-7785-cqjm-vp4q When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-764w-vr4w-hf3x Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 76. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-75p5-w5j4-v8qj Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
GHSA-7526-6xhc-xh2w During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-748v-pxm5-9m8q Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106. | CVSS3: 3.3 | 0% Низкий | около 3 лет назад | |
GHSA-73hr-36wp-4xmc Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password. | CVSS3: 5 | 0% Низкий | больше 3 лет назад | |
GHSA-737f-pfm5-cmq6 If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the <code>ThirdPartyUtil</code> component. This vulnerability affects Firefox < 106. | CVSS3: 7.1 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу