Vulnerabilities > Mozilla > Firefox > 70.0.1

DATE CVE VULNERABILITY TITLE RISK
2020-01-08 CVE-2019-17009 When running, the updater service wrote status and log files to an unrestricted location; potentially allowing an unprivileged process to locate and exploit a vulnerability in file handling in the updater service.
local
low complexity
mozilla opensuse
7.8
2020-01-08 CVE-2019-17008 Use After Free vulnerability in multiple products
When using nested workers, a use-after-free could occur during worker destruction.
network
low complexity
mozilla opensuse CWE-416
8.8
2020-01-08 CVE-2019-17005 Out-of-bounds Write vulnerability in multiple products
The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash.
network
low complexity
mozilla opensuse canonical CWE-787
8.8
2020-01-08 CVE-2019-11756 Use After Free vulnerability in Mozilla Firefox
Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service).
network
low complexity
mozilla CWE-416
8.8
2020-01-08 CVE-2019-11745 Out-of-bounds Write vulnerability in multiple products
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur.
8.8