Mozilla
mozilla
3,581 CVEs • 43 products
Products (43)
Click to collapseToggle
Products (43)
Click to collapse
CVEs (3,581)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Mozilla 3Firefox Firefox EsrThunderbirdJun 17, 2026 Dec 9, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 In certain circumstances, the MCallGetProperty opcode can be emitted with unmet assumptions resulting in an exploitable use-after-free condition. This vulnerability affects Firefox < 82.0.3, Firefox ESR < 78.4.1, and Thu...Show more |
When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-magnetic trace of a fe...Show more |
Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrar...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 22, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 81 and Firefox ESR 78.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of thes...Show more |
When a link to an external protocol was clicked, a prompt was presented that allowed the user to choose what application to open it in. An attacker could induce that prompt to be associated with an origin they didn't con...Show more |
When multiple WASM threads had a reference to a module, and were looking up exported functions, one WASM thread could have overwritten another's entry in a shared stub table, resulting in a potentially exploitable crash....Show more |
If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to success...Show more |
2Mozilla Siemens9Network Security Services Ruggedcom Rox Mx5000 FirmwareRuggedcom Rox Rx1400 Firmware+6 moreJun 17, 2026 Oct 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Network Security Services before 3.44, a malformed Netscape Certificate Sequence can cause NSS to crash, resulting in a denial of service. |
3Mozilla NetappSiemens13Hci Compute Node Hci Management NodeHci Storage Node+10 moreJun 17, 2026 Oct 22, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result...Show more |
2Mozilla Siemens9Network Security Services Ruggedcom Rox Mx5000 FirmwareRuggedcom Rox Rx1400 Firmware+6 moreNov 21, 2024 Oct 22, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Network Security Services (NSS) before 3.36.7 and before 3.41.1, a malformed signature can cause a crash due to a null dereference, resulting in a Denial of Service. |
4Fedoraproject MozillaOracle+1 more6Communications Offline Mediation Controller Communications Pricing Design CenterEnterprise Linux+3 moreJun 17, 2026 Oct 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library....Show more |
If an attacker intercepts Thunderbird's initial attempt to perform automatic account setup using the Microsoft Exchange autodiscovery mechanism, and the attacker sends a crafted response, then Thunderbird sends username...Show more |
During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affect...Show more |
When converting coordinates from projective to affine, the modular inversion was not performed in constant time, resulting in a possible timing-based side channel attack. This vulnerability affects Firefox < 80 and Firef...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than th...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulne...Show more |
When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 81. |
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrar...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more |