Show filters
62 Total Results
Displaying 21-30 of 62
Sort by:
Attacker Value
Unknown
CVE-2023-29543
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
0
Attacker Value
Unknown
CVE-2023-29541
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
0
Attacker Value
Unknown
CVE-2023-29540
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
0
Attacker Value
Unknown
CVE-2023-29539
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
0
Attacker Value
Unknown
CVE-2023-29538
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
0
Attacker Value
Unknown
CVE-2023-29537
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
Multiple race conditions in the font initialization could have led to memory corruption and execution of attacker-controlled code. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.
0
Attacker Value
Unknown
CVE-2023-29536
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
An attacker could cause the memory manager to incorrectly free a pointer that addresses attacker-controlled memory, resulting in an assertion, memory corruption, or a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
0
Attacker Value
Unknown
CVE-2023-29535
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
Following a Garbage Collector compaction, weak maps may have been accessed before they were correctly traced. This resulted in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
0
Attacker Value
Unknown
CVE-2023-29533
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
A website could have obscured the fullscreen notification by using a combination of <code>window.open</code>, fullscreen requests, <code>window.name</code> assignments, and <code>setInterval</code> calls. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.
0
Attacker Value
Unknown
CVE-2023-25743
Disclosure Date: June 02, 2023 (last updated October 08, 2023)
A lack of in app notification for entering fullscreen mode could have lead to a malicious website spoofing browser chrome.<br>*This bug only affects Firefox Focus. Other versions of Firefox are unaffected.*. This vulnerability affects Firefox < 110 and Firefox ESR < 102.8.
0