Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Mozilla Firefox, Firefox ESR, and Thunderbird contain a use-after-free vulnerability in SVG Animation, targeting Firefox and Tor browser users on Windows. Required action: Apply updates per vendor instructions.
CVE-2016-9079EPSS 87.6%Firefox, Firefox ESR, and ThunderbirdMozilla
Moxilla Firefox allows remote attackers to bypass the Same Origin Policy to read arbitrary files or gain privileges. Required action: Apply updates per vendor instructions.
Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. Required action: Apply updates per vendor instructions.
CVE-2019-11707EPSS 38.0%Firefox and ThunderbirdMozilla
Mozilla Firefox and Thunderbird contain a sandbox escape vulnerability that could result in remote code execution. Required action: Apply updates per vendor instructions.
CVE-2019-11708EPSS 55.9%Firefox and ThunderbirdMozilla
Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. Required action: Apply updates per vendor instructions.
CVE-2013-1690EPSS 69.0%Firefox and ThunderbirdMozilla
Mozilla Firefox contains a use-after-free vulnerability in WebGPU IPC Framework which can be exploited to perform arbitrary code execution. Required action: Apply updates per vendor instructions.
Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. Required action: Apply updates per vendor instructions.
Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. Required action: Apply updates per vendor instructions.
Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.
CVE-2020-6819EPSS 3.0%Firefox and ThunderbirdMozilla
Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.
CVE-2020-6820EPSS 6.3%Firefox and ThunderbirdMozilla
Mozilla Firefox and Thunderbird contain a type confusion vulnerability due to incorrect alias information in the IonMonkey JIT compiler when setting array elements. Required action: Apply updates per vendor instructions.
CVE-2019-17026EPSS 43.4%Firefox and ThunderbirdMozilla