Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

nvd логотип

CVE-2018-5173

около 8 лет назад

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-5173

около 8 лет назад

The filename appearing in the "Downloads" panel improperly renders som ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-5172

около 8 лет назад

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-5172

около 8 лет назад

The Live Bookmarks page and the PDF viewer can run injected script con ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-5169

около 8 лет назад

If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-5169

около 8 лет назад

If manipulated hyperlinked text with "chrome:" URL contained in it is ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-5168

около 8 лет назад

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-5168

около 8 лет назад

Sites can bypass security checks on permissions to install lightweight ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-5167

около 8 лет назад

The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into clicking by malicious sites. This vulnerability affects Firefox < 60.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-5167

около 8 лет назад

The web console and JavaScript debugger do not sanitize all output tha ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-5173

The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially executable files from user view in the panel. Note: the dialog to open the file will show the full, correct filename and whether it is executable or not. This vulnerability affects Firefox < 60.

CVSS3: 5.3
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5173

The filename appearing in the "Downloads" panel improperly renders som ...

CVSS3: 5.3
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5172

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5172

The Live Bookmarks page and the PDF viewer can run injected script con ...

CVSS3: 4.3
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5169

If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the home page tabs. This vulnerability affects Firefox < 60.

CVSS3: 6.5
1%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5169

If manipulated hyperlinked text with "chrome:" URL contained in it is ...

CVSS3: 6.5
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5168

Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without user interaction which could contain offensive or embarrassing images. This vulnerability affects Thunderbird < 52.8, Thunderbird ESR < 52.8, Firefox < 60, and Firefox ESR < 52.8.

CVSS3: 5.3
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5168

Sites can bypass security checks on permissions to install lightweight ...

CVSS3: 5.3
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5167

The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be able to directly link to internal chrome pages. Additionally, the JavaScript debugger will display "javascript:" links, which users could be tricked into clicking by malicious sites. This vulnerability affects Firefox < 60.

CVSS3: 4.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5167

The web console and JavaScript debugger do not sanitize all output tha ...

CVSS3: 4.3
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться