target entity

Mozilla

13 source-linked records in the current knowledge graph.

high

CVE-2010-3765: Mozilla Multiple Products Remote Code Execution Vulnerability

Mozilla Firefox, SeaMonkey, and Thunderbird contain an unspecified vulnerability when JavaScript is enabled. This allows remote attackers to execute arbitrary code via vectors related to nsCSSFrameConstructor::ContentAppended, the appendChild method, incorrect index tracking, and the creation of multiple frames, which triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-3765EPSS 83.3%MozillaMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2024-9680: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-9680EPSS 23.2%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2019-11707: Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash. Required action: Apply updates per vendor instructions.

CVE-2019-11707EPSS 38.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2013-1690: Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability

Mozilla Firefox and Thunderbird do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial-of-service (DoS) or possibly execute malicious code via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2013-1690EPSS 69.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26485: Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox contains a use-after-free vulnerability in XSLT parameter processing which can be exploited to perform arbitrary code execution. Required action: Apply updates per vendor instructions.

CVE-2022-26485EPSS 14.3%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2013-1675: Mozilla Firefox Information Disclosure Vulnerability

Mozilla Firefox does not properly initialize data structures for the nsDOMSVGZoomEvent::mPreviousScale and nsDOMSVGZoomEvent::mNewScale functions, which allows remote attackers to obtain sensitive information from process memory via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2013-1675EPSS 6.7%FirefoxMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6819: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when running the nsDocShell destructor under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.

CVE-2020-6819EPSS 3.0%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution
high

CVE-2020-6820: Mozilla Firefox And Thunderbird Use-After-Free Vulnerability

Mozilla Firefox and Thunderbird contain a race condition vulnerability when handling a ReadableStream under certain conditions. The race condition creates a use-after-free vulnerability, causing unspecified impacts. Required action: Apply updates per vendor instructions.

CVE-2020-6820EPSS 6.3%Firefox and ThunderbirdMozilla
CISA KEV ↗ · unattributed attribution