Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2018-12370

почти 8 лет назад

In Reader View SameSite cookie protections are not checked on exiting. ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-12369

почти 8 лет назад

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-12369

почти 8 лет назад

WebExtensions bundled with embedded experiments were not correctly che ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-12368

почти 8 лет назад

Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open permission to execute arbitrary code without user interaction on Windows 10 systems. *Note: this issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2018-12368

почти 8 лет назад

Windows 10 does not warn users before opening executable files with th ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2018-12367

почти 8 лет назад

In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-12367

почти 8 лет назад

In the previous mitigations for Spectre, the resolution or precision o ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-12366

почти 8 лет назад

An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-12366

почти 8 лет назад

An invalid grid size during QCMS (color profile) transformations can r ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-12365

почти 8 лет назад

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-12370

In Reader View SameSite cookie protections are not checked on exiting. ...

CVSS3: 8.8
1%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12369

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.

CVSS3: 9.8
3%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12369

WebExtensions bundled with embedded experiments were not correctly che ...

CVSS3: 9.8
3%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12368

Windows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded from the internet and have the "Mark of the Web." Without the warning, unsuspecting users unfamiliar with this new file type might run an unwanted executable. This also allows a WebExtension with the limited downloads.open permission to execute arbitrary code without user interaction on Windows 10 systems. *Note: this issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 8.1
5%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12368

Windows 10 does not warn users before opening executable files with th ...

CVSS3: 8.1
5%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12367

In the previous mitigations for Spectre, the resolution or precision of various methods was reduced to counteract the ability to measure precise time intervals. In that work PerformanceNavigationTiming was not adjusted but it was found that it could be used as a precision timer. This vulnerability affects Thunderbird < 60, Firefox ESR < 60.1, and Firefox < 61.

CVSS3: 4.3
2%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12367

In the previous mitigations for Spectre, the resolution or precision o ...

CVSS3: 4.3
2%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12366

An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
3%
Низкий
почти 8 лет назад
debian логотип
CVE-2018-12366

An invalid grid size during QCMS (color profile) transformations can r ...

CVSS3: 6.5
3%
Низкий
почти 8 лет назад
nvd логотип
CVE-2018-12365

A compromised IPC child process can escape the content sandbox and list the names of arbitrary files on the file system without user consent or interaction. This could result in exposure of private local files. This vulnerability affects Thunderbird < 60, Thunderbird < 52.9, Firefox ESR < 60.1, Firefox ESR < 52.9, and Firefox < 61.

CVSS3: 6.5
3%
Низкий
почти 8 лет назад

Уязвимостей на страницу


Поделиться