Vulnerabilities > Mozilla > Firefox

DATE CVE VULNERABILITY TITLE RISK
2023-06-02 CVE-2023-25739 Use After Free vulnerability in Mozilla Firefox ESR
Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>.
network
low complexity
mozilla CWE-416
8.8
2023-06-02 CVE-2023-25740 Unspecified vulnerability in Mozilla Firefox
After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system.
network
low complexity
mozilla
8.8
2023-06-02 CVE-2023-25741 Unspecified vulnerability in Mozilla Firefox
When dragging and dropping an image cross-origin, the image's size could potentially be leaked.
network
low complexity
mozilla
6.5
2023-06-02 CVE-2023-25742 Unspecified vulnerability in Mozilla Firefox ESR
When importing a SPKI RSA public key as ECDSA P-256, the key would be handled incorrectly causing the tab to crash.
network
low complexity
mozilla
6.5
2023-06-02 CVE-2023-25744 Out-of-bounds Write vulnerability in Mozilla Firefox ESR
Mmemory safety bugs present in Firefox 109 and Firefox ESR 102.7.
network
low complexity
mozilla CWE-787
8.8
2023-06-02 CVE-2023-25745 Out-of-bounds Write vulnerability in Mozilla Firefox
Memory safety bugs present in Firefox 109.
network
low complexity
mozilla CWE-787
8.8
2023-06-02 CVE-2023-25748 Unspecified vulnerability in Mozilla Firefox
By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks.
network
low complexity
mozilla
4.3
2023-06-02 CVE-2023-25749 Unspecified vulnerability in Mozilla Firefox
Android applications with unpatched vulnerabilities can be launched from a browser using Intents, exposing users to these vulnerabilities.
network
low complexity
mozilla
4.3
2023-06-02 CVE-2023-25750 Exposure of Resource to Wrong Sphere vulnerability in Mozilla Firefox
Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode.
network
low complexity
mozilla CWE-668
4.3
2023-06-02 CVE-2023-25751 Unspecified vulnerability in Mozilla Firefox
Sometimes, when invalidating JIT code while following an iterator, the newly generated code could be overwritten incorrectly.
network
low complexity
mozilla
6.5