Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

nvd логотип

CVE-2018-5166

около 8 лет назад

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-5166

около 8 лет назад

WebExtensions can use request redirection and a "filterReponseData" fi ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-5165

около 8 лет назад

In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn protections off. This vulnerability affects Firefox < 60.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-5165

около 8 лет назад

In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Ena ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-5164

около 8 лет назад

Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-5164

около 8 лет назад

Content Security Policy (CSP) is not applied correctly to all parts of ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-5163

около 8 лет назад

If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2018-5163

около 8 лет назад

If a malicious attacker has used another vulnerability to gain full co ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2018-5160

около 8 лет назад

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-5160

около 8 лет назад

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-5166

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5166

WebExtensions can use request redirection and a "filterReponseData" fi ...

CVSS3: 7.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5165

In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn protections off. This vulnerability affects Firefox < 60.

CVSS3: 5.3
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5165

In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Ena ...

CVSS3: 5.3
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5164

Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60.

CVSS3: 6.1
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5164

Content Security Policy (CSP) is not applied correctly to all parts of ...

CVSS3: 6.1
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5163

If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.

CVSS3: 8.1
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5163

If a malicious attacker has used another vulnerability to gain full co ...

CVSS3: 8.1
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5160

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.

CVSS3: 7.5
3%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5160

WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image ...

CVSS3: 7.5
3%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться