mozilla firefox esr
488 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
window.open with specifically set protocol handlers, an attacker could determine if the appliresource://devtools originresource://pdf.js origin.withPK11_Encrypt() in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel SaStreamFilter which could be used to read and modify theX-Frame-Options header, a sandboxed iframe could have presented a button that, if clicked by a usabout: dialog to show phishing content with an incorrect origin in the address bar. Thiunsafe-inline, the parent Content Security Policy could have overridden theEncryptingOutputStream was susceptible to exposing uninitialized data. This issue could only be abused in order to write data tShutdownObserver() was susceptible to potentially undefined behavior due to its reliance on a dynamic type that lacked a virnsDNSService::Init. This issue appears to manifest rarely during start-up. This vulnerabnsWindow::PickerOpen(void) method was susceptible to a heap buffer overflow when running in headless mode. This vulnerabilitVideoBridge allowed any content process to use textures produced by remote decoders. This could be abused to escape the sannsTextFragment due to insufficient OOM handling. This vulnerability affectsreadlink may actually be smaller than necessary. *This buDrawElementsInstanced method was susceptible to a heap buffer overflow when used on systems with the Mesa VM driver.PathRecording resulting in an out-of-bounds write, leadingFilterNodeD2D1 resulting in an out-of-bounds write, leadingHttpBaseChannel, if the load group was not available then it was ass.xll add-in files did not have a blocklist entry in Firefox's executable blocklist which allowed them to be downloaded witJS::CheckRegExpSyntax a Syntax Error could have been set which would end in calling convertToRuntimeErrorAndClearUpdateRegExpStatics attempted to access initialStringHeap it could already have been garbage collected prior to enteringRecordedSourceSurfaceCreation which resulted in a heap buffer overflow potentiallmStream could have been destroyed when initialized, which could have led to a use-after-fms-cxh and ms-cxh-full could have been leveraged to trigger a denial of service. *Note: This attack only affdatalist element to obscure the address bar. This vulnerability affects Firefox < 113, Firefconsole.log weren't accwindow.print() in a particular way, it could cause a denial of service of the browser, which may persist beychrome:// URLs as source text, some parameters were reflected. This vulnerability affects Fmk scheme which might allow attackers to launch paWM_COPYDATA messages that Firefox would process incorrectly, leading to an out-of