Vulnerabilities > Mozilla > Low
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-07-09 | CVE-2020-12405 | Use After Free vulnerability in multiple products When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. | 2.6 |
2020-07-09 | CVE-2020-12407 | Information Exposure vulnerability in Mozilla Firefox Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. | 2.6 |
2020-05-26 | CVE-2020-12392 | Path Traversal vulnerability in multiple products The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. | 2.1 |
2020-05-26 | CVE-2020-12394 | Unspecified vulnerability in Mozilla Firefox A logic flaw in our location bar implementation could have allowed a local attacker to spoof the current location by selecting a different origin and removing focus from the input element. | 2.1 |
2020-04-24 | CVE-2020-6824 | Session Fixation vulnerability in Mozilla Firefox Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. | 1.9 |
2020-01-08 | CVE-2019-17021 | Race Condition vulnerability in multiple products During the initialization of a new content process, a race condition occurs that can allow a content process to disclose heap addresses from the parent process. | 2.6 |
2019-02-28 | CVE-2018-12397 | Information Exposure vulnerability in Mozilla Firefox and Firefox ESR A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. | 3.6 |
2018-10-18 | CVE-2018-12383 | Insufficiently Protected Credentials vulnerability in multiple products If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. | 2.1 |
2018-06-11 | CVE-2016-5293 | Improper Input Validation vulnerability in multiple products When the Mozilla Updater is run, if the Updater's log file in the working directory points to a hardlink, data can be appended to an arbitrary local file. | 2.1 |
2018-06-11 | CVE-2016-5294 | Improper Input Validation vulnerability in Mozilla Firefox, Firefox ESR and Thunderbird The Mozilla Updater can be made to choose an arbitrary target working directory for output files resulting from the update process. | 2.1 |