CVEs (1,729)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreNov 21, 2024 Dec 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 By displaying a form validity message in the correct location at the same time as a permission prompt (such as for geolocation), the validity message could have obscured the prompt, resulting in the user potentially bein...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreNov 21, 2024 Dec 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Opportunistic Encryption feature of HTTP2 (RFC 8164) allows a connection to be transparently upgraded to TLS while retaining the visual properties of an HTTP connection, including being same-origin with unencrypted c...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreNov 21, 2024 Dec 8, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affect...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Dec 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Microsoft introduced a new feature in Windows 10 known as Cloud Clipboard which, if enabled, will record data copied to the clipboard to the cloud, and make it available on other computers in certain scenarios. Applicati...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreNov 21, 2024 Dec 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affect...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreNov 21, 2024 Dec 8, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thu...Show more |
2Debian Mozilla2Debian Linux ThunderbirdNov 21, 2024 Nov 3, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Thunderbird ignored the configuration to require STARTTLS security for an SMTP connection. A MITM could perform a downgrade attack to intercept transmitted messages, or could take control of the authenticated session to...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Nov 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreNov 21, 2024 Nov 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 92 and Firefox ESR 91.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Nov 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 During process shutdown, a document could have caused a use-after-free of a languages service object, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 93, Thunderbird...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Nov 3, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Through use of reportValidity() and window.open(), a plain-text validation message could have been overlaid on another origin, leading to possible user confusion and spoofing attacks. This vulnerability affects Firefox <...Show more |
2Debian Mozilla4Debian Linux FirefoxFirefox Esr+1 moreNov 21, 2024 Nov 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 During operations on MessageTasks, a task may have been removed while it was still scheduled, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.15, Thunderbir...Show more |
1Mozilla 2Firefox Esr ThunderbirdNov 21, 2024 Nov 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Thunderbird 78.13.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Nov 3, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 91 and Firefox ESR 78.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exp...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Nov 3, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 When delegating navigations to the operating system, Firefox would accept the `mk` scheme which might allow attackers to launch pages and execute scripts in Internet Explorer in unprivileged mode. *This bug only affects...Show more |
Firefox incorrectly accepted a newline in a HTTP/3 header, interpretting it as two separate headers. This allowed for a header splitting attack against servers using HTTP/3. This vulnerability affects Firefox < 91.0.1 an...Show more |
3Botan Project FedoraprojectMozilla3Botan FedoraThunderbirdNov 21, 2024 Sep 6, 2021 N/A· v4 5.9 MEDIUM· v3 2.6 LOW· v2 The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Aug 17, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 90 and Firefox ESR 78.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exp...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdNov 21, 2024 Aug 17, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Firefox incorrectly treated an inline list-item element as a block element, resulting in an out of bounds read or memory corruption, and a potentially exploitable crash. This vulnerability affects Thunderbird < 78.13, Th...Show more |
1Mozilla 2Firefox ThunderbirdNov 21, 2024 Aug 17, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 After requesting multiple permissions, and closing the first permission panel, subsequent permission panels will be displayed in a different position but still record a click in the default location, making it possible t...Show more |