Vulnerabilities > Mozilla > Firefox > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-19 | CVE-2023-6857 | Race Condition vulnerability in multiple products When resolving a symlink, a race may occur where the buffer passed to `readlink` may actually be smaller than necessary. | 5.3 |
2023-12-19 | CVE-2023-6860 | The `VideoBridge` allowed any content process to use textures produced by remote decoders. | 6.5 |
2023-12-19 | CVE-2023-6865 | `EncryptingOutputStream` was susceptible to exposing uninitialized data. | 6.5 |
2023-12-19 | CVE-2023-6867 | Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products The timing of a button click causing a popup to disappear was approximately the same length as the anti-clickjacking delay on permission prompts. | 6.1 |
2023-12-19 | CVE-2023-6868 | Unspecified vulnerability in Mozilla Firefox In some instances, the user-agent would allow push requests which lacked a valid VAPID even though the push manager subscription defined one. | 4.3 |
2023-12-19 | CVE-2023-6869 | Unspecified vulnerability in Mozilla Firefox A `<dialog>` element could have been manipulated to paint content outside of a sandboxed iframe. | 6.5 |
2023-12-19 | CVE-2023-6870 | Unspecified vulnerability in Mozilla Firefox Applications which spawn a Toast notification in a background thread may have obscured fullscreen notifications displayed by Firefox. | 4.3 |
2023-12-19 | CVE-2023-6871 | Unspecified vulnerability in Mozilla Firefox Under certain conditions, Firefox did not display a warning when a user attempted to navigate to a new protocol handler. | 4.3 |
2023-12-19 | CVE-2023-6872 | Unspecified vulnerability in Mozilla Firefox Browser tab titles were being leaked by GNOME to system logs. | 6.5 |
2023-11-21 | CVE-2023-49061 | Open Redirect vulnerability in Mozilla Firefox An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. | 6.1 |