Vulnerabilities > Mozilla > Critical

DATE CVE VULNERABILITY TITLE RISK
2023-06-19 CVE-2023-29531 Out-of-bounds Write vulnerability in Mozilla Firefox
An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS.
network
low complexity
mozilla CWE-787
critical
9.8
2023-06-19 CVE-2023-32216 Out-of-bounds Write vulnerability in Mozilla Firefox
Memory safety bugs present in Firefox 112.
network
low complexity
mozilla CWE-787
critical
9.8
2023-02-16 CVE-2021-43529 Out-of-bounds Write vulnerability in Mozilla Thunderbird
Thunderbird versions prior to 91.3.0 are vulnerable to the heap overflow described in CVE-2021-43527 when processing S/MIME messages.
network
low complexity
mozilla CWE-787
critical
9.8
2022-12-22 CVE-2021-4127 Unspecified vulnerability in Mozilla Thunderbird
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited.
network
low complexity
mozilla
critical
9.8
2022-12-22 CVE-2021-4129 Out-of-bounds Write vulnerability in Mozilla Firefox ESR
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported memory safety bugs present in Firefox 94.
network
low complexity
mozilla CWE-787
critical
9.8
2022-12-22 CVE-2021-4140 XML Injection (aka Blind XPath Injection) vulnerability in Mozilla Firefox
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox.
network
low complexity
mozilla CWE-91
critical
10.0
2022-12-22 CVE-2022-1887 SQL Injection vulnerability in Mozilla Firefox
The search term could have been specified externally to trigger SQL injection.
network
low complexity
mozilla CWE-89
critical
9.8
2022-12-22 CVE-2022-22759 Unspecified vulnerability in Mozilla Firefox
If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g.
network
low complexity
mozilla
critical
9.6
2022-12-22 CVE-2022-26384 Unspecified vulnerability in Mozilla Firefox
If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox.
network
low complexity
mozilla
critical
9.6
2022-12-22 CVE-2022-26486 Use After Free vulnerability in Mozilla products
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.
network
low complexity
mozilla CWE-416
critical
9.6