Vulnerabilities > Mozilla > Firefox > 0.6.1

DATE CVE VULNERABILITY TITLE RISK
2020-01-21 CVE-2011-2668 Unspecified vulnerability in Mozilla Firefox
Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header
network
mozilla
6.8
2020-01-13 CVE-2011-2670 Cross-site Scripting vulnerability in Mozilla Firefox
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
network
mozilla CWE-79
4.3
2020-01-08 CVE-2019-9812 Improper Input Validation vulnerability in Mozilla Firefox
Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account.
network
mozilla CWE-20
5.8
2020-01-08 CVE-2019-17025 Out-of-bounds Write vulnerability in multiple products
Mozilla developers reported memory safety bugs present in Firefox 71.
6.8
2020-01-08 CVE-2019-17024 Out-of-bounds Write vulnerability in multiple products
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3.
6.8
2020-01-08 CVE-2019-17023 Improper Authentication vulnerability in multiple products
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine.
network
low complexity
mozilla canonical debian CWE-287
6.5
2020-01-08 CVE-2019-17022 Cross-site Scripting vulnerability in Mozilla Firefox and Firefox ESR
When pasting a <style> tag from the clipboard into a rich text editor, the CSS sanitizer does not escape < and > characters.
4.3
2020-01-08 CVE-2019-17021 Race Condition vulnerability in multiple products
During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process.
network
high complexity
mozilla opensuse CWE-362
2.6
2020-01-08 CVE-2019-17020 Improper Input Validation vulnerability in multiple products
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet.
4.3
2020-01-08 CVE-2019-17019 Improper Input Validation vulnerability in Mozilla Firefox
When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download.
network
mozilla CWE-20
6.8