target entity

Firefox

5 source-linked records in the current knowledge graph.

high

CVE-2024-9680: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-9680EPSS 23.2%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26485: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. Required action: Apply updates per vendor instructions.

CVE-2022-26485EPSS 14.3%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2013-1675: Mozilla Firefox Information Disclosure Vulnerability

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2013-1675EPSS 6.7%FirefoxMozilla
CISA KEV ↗ · unattributed attribution