Vulnerabilities > Mozilla > High

DATE CVE VULNERABILITY TITLE RISK
2024-10-01 CVE-2024-9399 Unspecified vulnerability in Mozilla Thunderbird
A website configured to initiate a specially crafted WebTransport session could crash the Firefox process leading to a denial of service condition.
network
low complexity
mozilla
7.5
2024-09-17 CVE-2024-8900 Unspecified vulnerability in Mozilla Firefox
An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events.
network
low complexity
mozilla
7.5
2024-09-03 CVE-2024-8382 Unspecified vulnerability in Mozilla Firefox ESR
Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events.
network
low complexity
mozilla
8.8
2024-09-03 CVE-2024-8383 Unspecified vulnerability in Mozilla Firefox ESR
Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support.
network
low complexity
mozilla
7.5
2024-08-06 CVE-2024-7520 Type Confusion vulnerability in Mozilla Firefox
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution.
network
low complexity
mozilla CWE-843
8.8
2024-08-06 CVE-2024-7521 Improper Handling of Exceptional Conditions vulnerability in Mozilla Firefox
Incomplete WebAssembly exception handing could have led to a use-after-free.
network
low complexity
mozilla CWE-755
8.8
2024-08-06 CVE-2024-7522 Out-of-bounds Read vulnerability in Mozilla Firefox
Editor code failed to check an attribute value.
network
low complexity
mozilla CWE-125
8.8
2024-08-06 CVE-2024-7523 Unspecified vulnerability in Mozilla Firefox
A select option could partially obscure security prompts.
network
low complexity
mozilla
8.1
2024-08-06 CVE-2024-7525 Incorrect Default Permissions vulnerability in Mozilla Firefox
It was possible for a web extension with minimal permissions to create a `StreamFilter` which could be used to read and modify the response body of requests on any site.
network
low complexity
mozilla CWE-276
8.1
2024-08-06 CVE-2024-7527 Use After Free vulnerability in Mozilla Firefox
Unexpected marking work at the start of sweeping could have led to a use-after-free.
network
low complexity
mozilla CWE-416
8.8