Vulnerabilities > Mozilla > Firefox

DATE CVE VULNERABILITY TITLE RISK
2020-03-02 CVE-2020-6796 Out-of-bounds Write vulnerability in Mozilla Firefox
A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write.
network
low complexity
mozilla CWE-787
8.8
2020-03-02 CVE-2019-17026 Type Confusion vulnerability in multiple products
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.
network
low complexity
mozilla canonical CWE-843
8.8
2020-02-18 CVE-2013-5594 Improper Restriction of Rendered UI Layers or Frames vulnerability in Mozilla Firefox
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
network
low complexity
mozilla CWE-1021
4.3
2020-01-21 CVE-2011-2669 Improper Certificate Validation vulnerability in Mozilla Firefox
Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.
network
low complexity
mozilla CWE-295
6.5
2020-01-21 CVE-2011-2668 Unspecified vulnerability in Mozilla Firefox
Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header
network
low complexity
mozilla
8.8
2020-01-13 CVE-2011-2670 Cross-site Scripting vulnerability in Mozilla Firefox
Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets
network
low complexity
mozilla CWE-79
6.1
2020-01-08 CVE-2019-9812 Unspecified vulnerability in Mozilla Firefox
Given a compromised sandboxed content process due to a separate vulnerability, it is possible to escape that sandbox by loading accounts.firefox.com in that process and forcing a log-in to a malicious Firefox Sync account.
network
low complexity
mozilla
critical
9.3
2020-01-08 CVE-2019-17025 Out-of-bounds Write vulnerability in multiple products
Mozilla developers reported memory safety bugs present in Firefox 71.
network
low complexity
mozilla canonical CWE-787
8.8
2020-01-08 CVE-2019-17024 Out-of-bounds Write vulnerability in multiple products
Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3.
network
low complexity
mozilla canonical debian redhat opensuse CWE-787
8.8
2020-01-08 CVE-2019-17023 Improper Authentication vulnerability in multiple products
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine.
network
low complexity
mozilla canonical debian CWE-287
6.5