Vulnerabilities > Mozilla > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-06-19 | CVE-2023-29532 | Unspecified vulnerability in Mozilla Firefox A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. | 5.5 |
2023-06-19 | CVE-2023-32208 | Unspecified vulnerability in Mozilla Firefox Service workers could reveal script base URL due to dynamic `import()`. | 5.3 |
2023-06-19 | CVE-2023-32210 | Unspecified vulnerability in Mozilla Firefox Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. | 6.5 |
2023-06-02 | CVE-2023-0430 | Improper Certificate Validation vulnerability in Mozilla Thunderbird Certificate OCSP revocation status was not checked when verifying S/Mime signatures. | 6.5 |
2023-06-02 | CVE-2023-0547 | Improper Certificate Validation vulnerability in Mozilla Thunderbird OCSP revocation status of recipient certificates was not checked when sending S/Mime encrypted email, and revoked certificates would be accepted. | 6.5 |
2023-06-02 | CVE-2023-0616 | Resource Exhaustion vulnerability in Mozilla Thunderbird If a MIME email combines OpenPGP and OpenPGP MIME data in a certain way Thunderbird repeatedly attempts to process and display the message, which could cause Thunderbird's user interface to lock up and no longer respond to the user's actions. | 6.5 |
2023-06-02 | CVE-2023-1945 | Out-of-bounds Write vulnerability in Mozilla Thunderbird Unexpected data returned from the Safe Browsing API could have led to memory corruption and a potentially exploitable crash. | 6.5 |
2023-06-02 | CVE-2023-23597 | Inadequate Encryption Strength vulnerability in Mozilla Firefox A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the <code>file://</code> context. | 6.5 |
2023-06-02 | CVE-2023-23598 | Unspecified vulnerability in Mozilla Firefox Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to <code>DataTransfer.setData</code>. | 6.5 |
2023-06-02 | CVE-2023-23599 | Improper Encoding or Escaping of Output vulnerability in Mozilla Firefox When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. | 6.5 |