Vulnerabilities > Mozilla > Firefox > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-02 CVE-2023-29551 Out-of-bounds Write vulnerability in Mozilla Firefox and Focus
Memory safety bugs present in Firefox 111.
network
low complexity
mozilla CWE-787
8.8
2023-06-02 CVE-2023-32207 Authentication Bypass by Spoofing vulnerability in Mozilla Firefox
A missing delay in popup notifications could have made it possible for an attacker to trick a user into granting permissions.
network
low complexity
mozilla CWE-290
8.8
2023-06-02 CVE-2023-32213 Use of Uninitialized Resource vulnerability in Mozilla Firefox
When reading a file, an uninitialized value could have been used as read limit.
network
low complexity
mozilla CWE-908
8.8
2023-06-02 CVE-2023-32215 Out-of-bounds Write vulnerability in Mozilla Firefox
Memory safety bugs present in Firefox 112 and Firefox ESR 102.10.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-0511 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-0843 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-1529 Unspecified vulnerability in Mozilla Thunderbird
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototype pollution and ultimately attacker-controlled JavaScript executing in the privileged parent process.
network
low complexity
mozilla
8.8
2022-12-22 CVE-2022-1802 Unspecified vulnerability in Mozilla Thunderbird
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attacker-controlled JavaScript code in a privileged context.
network
low complexity
mozilla
8.8
2022-12-22 CVE-2022-22736 Uncontrolled Search Path Element vulnerability in Mozilla Firefox
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for system libraries.
local
high complexity
mozilla CWE-427
7.0
2022-12-22 CVE-2022-22737 Race Condition vulnerability in Mozilla Firefox
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows.
network
high complexity
mozilla CWE-362
7.5