Show filters
147 Total Results
Displaying 31-40 of 147
Sort by:
Attacker Value
Unknown

CVE-2019-17023

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.
Attacker Value
Unknown

CVE-2019-17017

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 68.4 and Firefox < 72.
Attacker Value
Unknown

CVE-2019-17012

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Attacker Value
Unknown

CVE-2019-17005

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Attacker Value
Unknown

CVE-2019-17020

Disclosure Date: January 08, 2020 (last updated February 21, 2025)
If an XML file is served with a Content Security Policy and the XML file includes an XSL stylesheet, the Content Security Policy will not be applied to the contents of the XSL stylesheet. If the XSL sheet e.g. includes JavaScript, it would bypass any of the restrictions of the Content Security Policy applied to the XML document. This vulnerability affects Firefox < 72.
Attacker Value
Unknown

CVE-2019-11740

Disclosure Date: September 27, 2019 (last updated November 27, 2024)
Mozilla developers and community members reported memory safety bugs present in Firefox 68, Firefox ESR 68, and Firefox 60.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.
Attacker Value
Unknown

CVE-2019-11745

Disclosure Date: August 14, 2019 (last updated February 21, 2025)
When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.
Attacker Value
Unknown

CVE-2019-17025

Disclosure Date: March 11, 2019 (last updated February 21, 2025)
Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 72.
Attacker Value
Unknown

CVE-2018-12399

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.
0
Attacker Value
Unknown

CVE-2018-18495

Disclosure Date: February 28, 2019 (last updated November 27, 2024)
WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.
0