Multiple Vulnerabilities in Mozilla Products Could Allow for Arbitrary Code Execution
ID: 446ddf50-81ff-58c0-9e0d-36e41894320c
STIX ID: report--446ddf50-81ff-58c0-9e0d-36e41894320c
Feed Name: CISecurity.org Advisories
Multiple vulnerabilities have been disclosed in Mozilla products (Firefox, Firefox Focus for Android, Thunderbird), including memory-safety bugs and cross-origin/multipart response flaws (several CVEs) that could lead to arbitrary code execution, cross-origin data access, UI spoofing, or denial-of-service; affected releases include Firefox 131, ESR versions, and Thunderbird builds. The advisory details individual issues (e.g., preventing exit from full-screen, loading cross-origin pages, PDF/JSON multipart access, clipboard write bypass) and notes that successful exploitation could let attackers install programs or access/modify/delete data; no evidence of active exploitation is included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
