Vulnerabilities > Mozilla > Firefox ESR

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2019-11745 Out-of-bounds Write vulnerability in multiple products
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur.
8.8
2019-09-27 CVE-2019-11753 Improper Validation of Integrity Check Value vulnerability in Mozilla Firefox
The Firefox installer allows Firefox to be installed to a custom user writable location, leaving it unprotected from manipulation by unprivileged users or malware.
local
low complexity
mozilla CWE-354
7.8
2019-09-27 CVE-2019-11752 Use After Free vulnerability in Mozilla Firefox
It is possible to delete an IndexedDB key value and subsequently try to extract it during conversion.
network
low complexity
mozilla CWE-416
8.8
2019-09-27 CVE-2019-11751 Argument Injection or Modification vulnerability in Mozilla Firefox
Logging-related command line parameters are not properly sanitized when Firefox is launched by another program, such as when a user clicks on malicious links in a chat application.
network
low complexity
mozilla CWE-88
8.8
2019-09-27 CVE-2019-11750 Use of Uninitialized Resource vulnerability in Mozilla Firefox
A type confusion vulnerability exists in Spidermonkey, which results in a non-exploitable crash.
network
low complexity
mozilla CWE-908
6.5
2019-09-27 CVE-2019-11749 Unspecified vulnerability in Mozilla Firefox
A vulnerability exists in WebRTC where malicious web content can use probing techniques on the getUserMedia API using constraints to reveal device properties of cameras on the system without triggering a user prompt or notification.
network
low complexity
mozilla
4.3
2019-09-27 CVE-2019-11748 Improper Preservation of Permissions vulnerability in Mozilla Firefox
WebRTC in Firefox will honor persisted permissions given to sites for access to microphone and camera resources even when in a third-party context.
network
low complexity
mozilla CWE-281
6.5
2019-09-27 CVE-2019-11747 Improper Initialization vulnerability in Mozilla Firefox
The "Forget about this site" feature in the History pane is intended to remove all saved user data that indicates a user has visited a site.
network
low complexity
mozilla CWE-665
6.5
2019-09-27 CVE-2019-11746 Use After Free vulnerability in Mozilla Firefox
A use-after-free vulnerability can occur while manipulating video elements if the body is freed while still in use.
network
low complexity
mozilla CWE-416
8.8
2019-09-27 CVE-2019-11744 Cross-site Scripting vulnerability in Mozilla Firefox
Some HTML elements, such as <title> and <textarea>, can contain literal angle brackets without treating them as markup.
network
low complexity
mozilla CWE-79
6.1