Vulnerabilities > Mozilla > Firefox

DATE CVE VULNERABILITY TITLE RISK
2021-03-31 CVE-2021-23985 Unspecified vulnerability in Mozilla Firefox
If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user.
network
low complexity
mozilla
6.5
2021-03-31 CVE-2021-23984 Authentication Bypass by Spoofing vulnerability in Mozilla Firefox
A malicious extension could have opened a popup window lacking an address bar.
network
low complexity
mozilla CWE-290
6.5
2021-03-31 CVE-2021-23983 Out-of-bounds Write vulnerability in Mozilla Firefox
By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash.
network
low complexity
mozilla CWE-787
6.5
2021-03-31 CVE-2021-23982 Inadequate Encryption Strength vulnerability in Mozilla Firefox
Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections.
network
low complexity
mozilla CWE-326
6.5
2021-03-31 CVE-2021-23981 Out-of-bounds Write vulnerability in Mozilla Firefox
A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash.
network
low complexity
mozilla CWE-787
8.1
2021-02-26 CVE-2021-23979 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 85.
network
low complexity
mozilla CWE-787
8.8
2021-02-26 CVE-2021-23978 Out-of-bounds Write vulnerability in multiple products
Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7.
network
low complexity
mozilla debian CWE-787
8.8
2021-02-26 CVE-2021-23965 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 84.
network
low complexity
mozilla CWE-787
8.8
2021-02-26 CVE-2021-23964 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 84 and Firefox ESR 78.6.
network
low complexity
mozilla CWE-787
8.8
2021-02-26 CVE-2021-23977 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Mozilla Firefox
Firefox for Android suffered from a time-of-check-time-of-use vulnerability that allowed a malicious application to read sensitive data from application directories.
network
high complexity
mozilla CWE-367
5.3