By injecting a cookie with certain special characters, an attacker on a shared subdomain which is not a secure context could set and thus overwrite c…
During iframe navigation, certain pages did not have their FeaturePolicy fully initialized leading to a bypass that leaked device permissions into un…
Concurrent use of the URL parser with non-UTF-8 data was not thread-safe. This could lead to a use-after-free causing a potentially exploitable crash…
During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This iss…
When saving or opening an email attachment on macOS, Thunderbird did not set attribute com.apple.quarantine on the received file. If the received fil…
Inconsistent data in instruction and data cache when creating wasm code could lead to a potentially exploitable crash.<br>*This bug only affects Fire…
When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vuln…
An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 1…
Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these b…
Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs sho…
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv=…
A data race could occur in the <code>PK11_ChangePW</code> function, potentially leading to a use-after-free vulnerability. In Firefox, this lock prot…
When receiving an HTML email that contained an <code>iframe</code> element, which used a <code>srcdoc</code> attribute to define the inner HTML docum…
Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corr…
A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerab…
An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar…
An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not …
When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerabili…
When visiting a website with an overly long URL, the user interface would start to hang. Due to session restore, this could lead to a permanent Denia…
When using the Performance API, an attacker was able to notice subtle differences between PerformanceEntries and thus learn whether the target URL ha…
When visiting directory listings for `chrome://` URLs as source text, some parameters were reflected. This vulnerability affects Firefox ESR < 102.1,…
Mozilla developers Bryce Seager van Dyk and the Mozilla Fuzzing Team reported potential vulnerabilities present in Firefox 101. Some of these bugs sh…
The Mozilla Fuzzing Team reported potential vulnerabilities present in Thunderbird 91.10. Some of these bugs showed evidence of memory corruption and…
When opening a Windows shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from…
Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite…
In the <code>nsTArray_Impl::ReplaceElementsAt()</code> function, an integer overflow could have occurred when the number of elements to replace was t…
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe…
An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an exe…
A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential us…
ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability af…