Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

fstec логотип

BDU:2019-01571

больше 7 лет назад

Уязвимость библиотеки Skia используемой веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-18506

больше 7 лет назад

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-18506

больше 7 лет назад

When proxy auto-detection is enabled, if a web server serves a Proxy A ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2018-18505

больше 7 лет назад

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2018-18505

больше 7 лет назад

An earlier fix for an Inter-process Communication (IPC) vulnerability, ...

CVSS3: 10
EPSS: Низкий
nvd логотип

CVE-2018-18504

больше 7 лет назад

A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possibility of reading from the memory of the freed buffers. This vulnerability affects Firefox < 65.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-18504

больше 7 лет назад

A crash and out-of-bounds read can occur when the buffer of a texture ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-18503

больше 7 лет назад

When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-18503

больше 7 лет назад

When JavaScript is used to create and manipulate an audio buffer, a po ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-18502

больше 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2019-01571

Уязвимость библиотеки Skia используемой веб-браузеров Firefox, Firefox ESR и программы для работы с электронной почтой Thunderbird, связанная с целочисленным переполнением, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18506

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.

CVSS3: 5.9
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18506

When proxy auto-detection is enabled, if a web server serves a Proxy A ...

CVSS3: 5.9
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18505

An earlier fix for an Inter-process Communication (IPC) vulnerability, CVE-2011-3079, added authentication to communication between IPC endpoints and server parents during IPC process creation. This authentication is insufficient for channels created after the IPC process is started, leading to the authentication not being correctly applied to later channels. This could allow for a sandbox escape through IPC channels due to lack of message validation in the listener process. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

CVSS3: 10
5%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18505

An earlier fix for an Inter-process Communication (IPC) vulnerability, ...

CVSS3: 10
5%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18504

A crash and out-of-bounds read can occur when the buffer of a texture client is freed while it is still in use during graphic operations. This results is a potentially exploitable crash and the possibility of reading from the memory of the freed buffers. This vulnerability affects Firefox < 65.

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18504

A crash and out-of-bounds read can occur when the buffer of a texture ...

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18503

When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18503

When JavaScript is used to create and manipulate an audio buffer, a po ...

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18502

Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.

CVSS3: 9.8
2%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться