Show filters
331 Total Results
Displaying 51-60 of 331
Sort by:
Attacker Value
Unknown

CVE-2023-37202

Disclosure Date: July 05, 2023 (last updated October 08, 2023)
Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Attacker Value
Unknown

CVE-2023-37201

Disclosure Date: July 05, 2023 (last updated October 08, 2023)
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.
Attacker Value
Unknown

CVE-2022-46877

Disclosure Date: December 22, 2022 (last updated October 08, 2023)
By confusing the browser, the fullscreen notification could have been delayed or suppressed, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 108.
Attacker Value
Unknown

CVE-2022-46871

Disclosure Date: December 22, 2022 (last updated October 08, 2023)
An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.
Attacker Value
Unknown

CVE-2021-43546

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
It was possible to recreate previous cursor spoofing attacks against users with a zoomed native cursor. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43545

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Using the Location API in a loop could have caused severe application hangs and crashes. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43543

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Documents loaded with the CSP sandbox directive could have escaped the sandbox's script restriction by embedding additional content. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43542

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43541

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
When invoking protocol handlers for external protocols, a supplied parameter URL containing spaces was not properly escaped. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
Attacker Value
Unknown

CVE-2021-43539

Disclosure Date: December 08, 2021 (last updated February 23, 2025)
Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.