Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

nvd логотип

CVE-2018-5147

около 8 лет назад

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-5147

около 8 лет назад

The libtremor library has the same flaw as CVE-2018-5146. This library ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-5146

около 8 лет назад

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2018-5146

около 8 лет назад

An out of bounds memory write while processing Vorbis audio data was r ...

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2018-5145

около 8 лет назад

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-5145

около 8 лет назад

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showe ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-5144

около 8 лет назад

An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

CVSS3: 7.3
EPSS: Низкий
debian логотип

CVE-2018-5144

около 8 лет назад

An integer overflow can occur during conversion of text to some Unicod ...

CVSS3: 7.3
EPSS: Низкий
nvd логотип

CVE-2018-5143

около 8 лет назад

URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Firefox < 59.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2018-5143

около 8 лет назад

URLs using "javascript:" have the protocol removed when pasted into th ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-5147

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

CVSS3: 9.8
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5147

The libtremor library has the same flaw as CVE-2018-5146. This library ...

CVSS3: 9.8
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5146

An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.

CVSS3: 8.8
12%
Средний
около 8 лет назад
debian логотип
CVE-2018-5146

An out of bounds memory write while processing Vorbis audio data was r ...

CVSS3: 8.8
12%
Средний
около 8 лет назад
nvd логотип
CVE-2018-5145

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

CVSS3: 9.8
3%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5145

Memory safety bugs were reported in Firefox ESR 52.6. These bugs showe ...

CVSS3: 9.8
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5144

An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.

CVSS3: 7.3
3%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5144

An integer overflow can occur during conversion of text to some Unicod ...

CVSS3: 7.3
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5143

URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Firefox < 59.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5143

URLs using "javascript:" have the protocol removed when pasted into th ...

CVSS3: 6.1
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться