Vulnerabilities > Mozilla > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-01-08 | CVE-2019-17005 | Out-of-bounds Write vulnerability in multiple products The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. | 8.8 |
2020-01-08 | CVE-2019-11764 | Out-of-bounds Write vulnerability in multiple products Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. | 8.8 |
2020-01-08 | CVE-2019-11760 | Out-of-bounds Write vulnerability in multiple products A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. | 8.8 |
2020-01-08 | CVE-2019-11759 | Classic Buffer Overflow vulnerability in multiple products An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. | 8.8 |
2020-01-08 | CVE-2019-11758 | Out-of-bounds Write vulnerability in multiple products Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. | 8.8 |
2020-01-08 | CVE-2019-11757 | Use After Free vulnerability in multiple products When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. | 8.8 |
2020-01-08 | CVE-2019-11756 | Use After Free vulnerability in Mozilla Firefox Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). | 8.8 |
2020-01-08 | CVE-2019-11745 | Out-of-bounds Write vulnerability in multiple products When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. | 8.8 |
2019-11-15 | CVE-2016-5285 | NULL Pointer Dereference vulnerability in multiple products A Null pointer dereference vulnerability exists in Mozilla Network Security Services due to a missing NULL check in PK11_SignWithSymKey / ssl3_ComputeRecordMACConstantTime, which could let a remote malicious user cause a Denial of Service. | 7.5 |
2019-09-27 | CVE-2019-11755 | Improper Verification of Cryptographic Signature vulnerability in Mozilla Thunderbird A crafted S/MIME message consisting of an inner encryption layer and an outer SignedData layer was shown as having a valid digital signature, although the signer might have had no access to the contents of the encrypted message, and might have stripped a different signature from the encrypted message. | 7.5 |