Vulnerabilities > Mozilla > High

DATE CVE VULNERABILITY TITLE RISK
2022-12-22 CVE-2022-46881 Out-of-bounds Write vulnerability in Mozilla Firefox
An optimization in WebGL was incorrect in some cases, and could have led to memory corruption and a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after we better understood the impact of the issue.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-46883 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106.
network
low complexity
mozilla CWE-787
8.8
2022-12-22 CVE-2022-46885 Out-of-bounds Write vulnerability in Mozilla Firefox
Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105.
network
low complexity
mozilla CWE-787
8.8
2022-11-19 CVE-2022-4066 A vulnerability was found in davidmoreno onion.
network
low complexity
mozilla onion-project
8.2
2022-10-14 CVE-2022-3479 Unspecified vulnerability in Mozilla Network Security Services 3.77
A vulnerability found in nss.
network
low complexity
mozilla
7.5
2022-05-05 CVE-2022-29167 Unspecified vulnerability in Mozilla Hawk
Hawk is an HTTP authentication scheme providing mechanisms for making authenticated HTTP requests with partial cryptographic verification of the request and response, covering the HTTP method, request URI, host, and optionally the request payload.
network
low complexity
mozilla
7.5
2021-12-08 CVE-2021-38504 Use After Free vulnerability in multiple products
When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash.
network
low complexity
mozilla debian CWE-416
8.8
2021-12-08 CVE-2021-38510 Unspecified vulnerability in Mozilla Firefox
The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems.
network
low complexity
mozilla
8.8
2021-12-08 CVE-2021-43534 Out-of-bounds Write vulnerability in multiple products
Mozilla developers and community members reported memory safety bugs present in Firefox 93 and Firefox ESR 91.2.
network
low complexity
mozilla debian CWE-787
8.8
2021-12-08 CVE-2021-43535 Use After Free vulnerability in multiple products
A use-after-free could have occured when an HTTP2 session object was released on a different thread, leading to memory corruption and a potentially exploitable crash.
network
low complexity
mozilla debian CWE-416
8.8