Vulnerabilities > Mozilla > Firefox > Critical

DATE CVE VULNERABILITY TITLE RISK
2021-08-05 CVE-2021-29971 Improper Preservation of Permissions vulnerability in Mozilla Firefox
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission.
network
low complexity
mozilla CWE-281
critical
9.8
2021-01-07 CVE-2020-26972 Use After Free vulnerability in Mozilla Firefox
The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to.
network
low complexity
mozilla CWE-416
critical
9.8
2020-10-22 CVE-2020-15683 Use After Free vulnerability in multiple products
Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3.
network
low complexity
mozilla debian opensuse CWE-416
critical
9.8
2020-10-22 CVE-2020-15684 Use After Free vulnerability in Mozilla Firefox
Mozilla developers reported memory safety bugs present in Firefox 81.
network
low complexity
mozilla CWE-416
critical
9.8
2020-05-26 CVE-2020-12388 Improper Input Validation vulnerability in Mozilla Firefox
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.
network
low complexity
mozilla CWE-20
critical
10.0
2020-05-26 CVE-2020-12389 Improper Input Validation vulnerability in Mozilla Firefox
The Firefox content processes did not sufficiently lockdown access control which could result in a sandbox escape.
network
low complexity
mozilla CWE-20
critical
10.0
2020-05-26 CVE-2020-12390 Deserialization of Untrusted Data vulnerability in Mozilla Firefox
Incorrect origin serialization of URLs with IPv6 addresses could lead to incorrect security checks.
network
low complexity
mozilla CWE-502
critical
9.8
2020-05-26 CVE-2020-6831 Out-of-bounds Write vulnerability in multiple products
A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC.
network
low complexity
mozilla canonical debian opensuse CWE-787
critical
9.8
2020-05-26 CVE-2020-12395 Out-of-bounds Write vulnerability in multiple products
Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7.
network
low complexity
mozilla canonical CWE-787
critical
9.8
2020-05-26 CVE-2020-12396 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers and community members reported memory safety bugs present in Firefox 75.
network
low complexity
mozilla CWE-787
critical
9.8