Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2018-12386

почти 8 лет назад

A vulnerability in register allocation in JavaScript can lead to type ...

CVSS3: 8.1
EPSS: Средний
nvd логотип

CVE-2018-12385

почти 8 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2018-12385

почти 8 лет назад

A potentially exploitable crash in TransportSecurityInfo used for SSL ...

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2018-12383

почти 8 лет назад

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2018-12383

почти 8 лет назад

If a user saved passwords before Firefox 58 and then later set a maste ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2018-12382

почти 8 лет назад

The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. This can lead to user confusion. *This vulnerability only affects Firefox for Android < 62.*

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-12382

почти 8 лет назад

The displayed addressbar URL can be spoofed on Firefox for Android usi ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-12381

почти 8 лет назад

Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-12381

почти 8 лет назад

Manually dragging and dropping an Outlook email message into the brows ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-12379

почти 8 лет назад

When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-12386

A vulnerability in register allocation in JavaScript can lead to type ...

CVSS3: 8.1
13%
Средний
почти 8 лет назад
nvd логотип
CVE-2018-12385

A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination with another vulnerability allowing an attacker to write data into the local cache or from locally installed malware. This issue also triggers a non-exploitable startup crash for users switching between the Nightly and Release versions of Firefox if the same profile is used. This vulnerability affects Thunderbird < 60.2.1, Firefox ESR < 60.2.1, and Firefox < 62.0.2.

CVSS3: 7
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12385

A potentially exploitable crash in TransportSecurityInfo used for SSL ...

CVSS3: 7
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12383

If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.

CVSS3: 5.5
0%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12383

If a user saved passwords before Firefox 58 and then later set a maste ...

CVSS3: 5.5
0%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12382

The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. This can lead to user confusion. *This vulnerability only affects Firefox for Android < 62.*

CVSS3: 5.3
2%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12382

The displayed addressbar URL can be spoofed on Firefox for Android usi ...

CVSS3: 5.3
2%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12381

Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.

CVSS3: 5.3
2%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12381

Manually dragging and dropping an Outlook email message into the brows ...

CVSS3: 5.3
2%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12379

When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

CVSS3: 7.8
0%
Низкий
почти 8 лет назад

Уязвимостей на страницу


Поделиться