Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.
Last updated 24 July 2024
Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing a malformed video and leveraging a Gecko Media Plugin (GMP) sandbox bypass.
Last updated 24 July 2024
A bad cast when processing layout with input elements can result in a potentially exploitable crash.
A use-after-free vulnerability with web animations when destroying a timeline
Due to flaws in the process we used to update "Preloaded Public Key Pinning" in our releases, the pinning for add-on updates became ineffective in early September. An attacker who was able to get a mis-issued certificate for a Mozilla web site could send malicious add-on updates to users on networks controlled by the attacker. Users who have not installed any add-ons are not affected.
A potentially exploitable crash caused by a buffer overflow while encoding image frames to images
Last updated 24 July 2024
Last updated 24 July 2024
An out-of-bounds write of a boolean value during text conversion with some unicode characters
A use-after-free vulnerability triggered by setting a aria-owns attribute
A use-after-free issue in web animations during restyling.
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024
Last updated 24 July 2024