Page 46 of 2503 results (0.013 seconds)

CVSS: 4.3EPSS: 0%CPEs: 5EXPL: 0

25 Feb 2021 — If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8. Si la Política de Seguridad de Contenido bloqueaba la navegación de tramas, el destino completo de un redireccionamiento servido en la trama se reportaba en el informe de... • https://bugzilla.mozilla.org/show_bug.cgi?id=1687342 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 8.8EPSS: 0%CPEs: 5EXPL: 0

25 Feb 2021 — Mozilla developers reported memory safety bugs present in Firefox 85 and Firefox ESR 78.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8. Los desarrolladores de Mozilla reportaron bugs de seguridad de la memoria presentes en Firefox versión 85 y Firefox ESR versión 78.7. Algunos de estos bugs mostraron evidenc... • https://bugzilla.mozilla.org/buglist.cgi?bug_id=786797%2C1682928%2C1687391%2C1687597 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE-787: Out-of-bounds Write •

CVSS: 6.5EPSS: 0%CPEs: 5EXPL: 0

25 Feb 2021 — When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8. Cuando se intenta cargar un recurso de origen cruzado en un contexto de audio y video, puede haber resultado un error de decodificación, y el contenido de ese error puede haber divulgado información sobre el recurso. Esta vulnerabilidad... • https://bugzilla.mozilla.org/show_bug.cgi?id=1690976 • CWE-209: Generation of Error Message Containing Sensitive Information •

CVSS: 4.3EPSS: 0%CPEs: 5EXPL: 0

25 Feb 2021 — As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the source file to be the destination of the redirects. This was fixed to be the redirect destination's origin. This vulnerability affects Firefox < 86, Thund... • https://bugzilla.mozilla.org/show_bug.cgi?id=1542194 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 0

01 Feb 2021 — The browser could have been confused into transferring a pointer lock state into another tab, which could have lead to clickjacking attacks. This vulnerability affects Firefox < 85. El navegador podría haber sido confundido al transferir un estado de bloqueo del puntero a otra pestaña, lo que podría haber conllevado a ataques de secuestro de clics. Esta vulnerabilidad afecta a Firefox versiones anteriores a 85 Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result ... • https://bugzilla.mozilla.org/show_bug.cgi?id=1684837 • CWE-1021: Improper Restriction of Rendered UI Layers or Frames •

CVSS: 4.3EPSS: 0%CPEs: 1EXPL: 0

01 Feb 2021 — When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85. Cuando se comparten la geolocalización durante un recurso compartido de WebRTC activo, Firefox podría haber restablecido el estado del intercambio de webRTC en la interfaz de usuario, conllevando a una pérdida de control sobre el permiso otorgado actualmente. Esta vulner... • https://bugzilla.mozilla.org/show_bug.cgi?id=1680793 • CWE-281: Improper Preservation of Permissions •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 1

01 Feb 2021 — An ambiguous file picker design could have confused users who intended to select and upload a single file into uploading a whole directory. This was addressed by adding a new prompt. This vulnerability affects Firefox < 85. Un diseño de selector de archivos ambiguos podría haber confundido a usuarios que pretendían seleccionar y cargar un solo archivo para cargar un directorio completo.&#xa0;Esto se solucionó al agregar un nuevo aviso. • https://bugzilla.mozilla.org/show_bug.cgi?id=1338637 •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 1

01 Feb 2021 — Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85. Los desarrolladores de Mozilla reportaron bugs de seguridad de la memoria presentes en Firefox versión 84. Algunos de estos bugs mostraron evidencia de corrupción de la memoria y suponemos que con esfuerzo suficiente algunos de ellos podrían h... • https://bugzilla.mozilla.org/buglist.cgi?bug_id=1670378%2C1673555%2C1676812%2C1678582%2C1684497 • CWE-787: Out-of-bounds Write •

CVSS: 8.8EPSS: 0%CPEs: 1EXPL: 0

01 Feb 2021 — Incorrect use of the '' method could have led to a user-after-poison and a potentially exploitable crash. This vulnerability affects Firefox < 85. Un uso incorrecto del método "(RowCountChanged)" podría conllevar a un uso posterior al envenenamiento y un bloqueo potencialmente explotable. Esta vulnerabilidad afecta a Firefox versiones anteriores a 85 Multiple vulnerabilities have been found in Mozilla Firefox, the worst of which could result in the arbitrary execution of code. Versions... • https://bugzilla.mozilla.org/show_bug.cgi?id=1677194 •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

01 Feb 2021 — The browser could have been confused into transferring a screen sharing state into another tab, which would leak unintended information. This vulnerability affects Firefox < 85. El navegador podría haber sido confundido en transferir un estado de pantalla compartida a otra pestaña, lo que filtraría información no deseada. Esta vulnerabilidad afecta a Firefox versiones anteriores a 85 Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, a... • https://bugzilla.mozilla.org/show_bug.cgi?id=1642747 • CWE-668: Exposure of Resource to Wrong Sphere •