A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) Service that could be abused to grant Users write access to an arbitrary directo…
If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grant…
After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is …
Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. T…
By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes t…
The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command inj…
Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91…
A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*Thi…
Applying a CSS filter effect could have accessed out of bounds memory. This could have lead to a heap-buffer-overflow causing a potentially exploitab…
Certain network request objects were freed too early when releasing a network request handle. This could have lead to a use-after-free causing a pote…
Constructing audio sinks could have lead to a race condition when playing audio files and closing windows. This could have lead to a use-after-free c…
When resizing a popup while requesting fullscreen access, the popup would have become unable to leave fullscreen mode. This vulnerability affects Fir…
If Firefox was installed to a world-writable directory, a local privilege escalation could occur when Firefox searched the current directory for syst…
Malicious websites could have tricked users into accepting launching a program to handle an external URL protocol. This vulnerability affects Firefox…
When inserting text while in edit mode, some characters might have lead to out-of-bounds memory access causing a potentially exploitable crash. This …
The search term could have been specified externally to trigger SQL injection. This vulnerability affects Firefox for iOS < 101.
An attacker could have sent a message to the parent process where the contents were used to double-index into a JavaScript object, leading to prototy…
If an attacker was able to corrupt the methods of an Array object in JavaScript via prototype pollution, they could have achieved execution of attack…
When displaying the sender of an email, and the sender name contained the Braille Pattern Blank space character multiple times, Thunderbird would hav…
When importing a revoked key that specified key compromise as the revocation reason, Thunderbird did not update the existing copy of the key that was…
It was possible to construct specific XSLT markup that would be able to bypass an iframe sandbox. This vulnerability affects Firefox ESR < 91.5, Fire…
Mozilla developers and community members Julian Hector, Randell Jesup, Gabriele Svelto, Tyson Smith, Christian Holler, and Masayuki Nakano reported m…
Mozilla developers and community members Gabriele Svelto, Sebastian Hengst, Randell Jesup, Luan Herrera, Lars T Hansen, and the Mozilla Fuzzing Team …
It may be possible for an attacker to craft an email message that causes Thunderbird to perform an out-of-bounds write of one byte when processing th…
Mozilla developers Kershaw Chang, Ryan VanderMeulen, and Randell Jesup reported memory safety bugs present in Firefox 97. Some of these bugs showed e…
Mozilla VPN can load an OpenSSL configuration file from an unsecured directory. A user or attacker with limited privileges could leverage this to lau…
<code>NSSToken</code> objects were referenced via direct points, and could have been accessed in an unsafe way on different threads, leading to a use…
After a VR Process is destroyed, a reference to it may have been retained and used, leading to a use-after-free and potentially exploitable crash. Th…
An out of date graphics library (Angle) likely contained vulnerabilities that could potentially be exploited. This vulnerability affects Thunderbird …
During the plaintext phase of the STARTTLS connection setup, protocol commands could have been injected and evaluated within the encrypted session. T…