Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

nvd логотип

CVE-2018-5113

около 8 лет назад

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-5113

около 8 лет назад

The "browser.identity.launchWebAuthFlow" function of WebExtensions is ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-5112

около 8 лет назад

Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-5112

около 8 лет назад

Development Tools panels of an extension are required to load URLs for ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-5111

около 8 лет назад

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-5111

около 8 лет назад

When the text of a specially formatted URL is dragged to the addressba ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-5110

около 8 лет назад

If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible within Firefox. Note: This vulnerability only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 58.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-5110

около 8 лет назад

If cursor visibility is toggled by script using from 'none' to an imag ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-5109

около 8 лет назад

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-5109

около 8 лет назад

An audio capture session can started under an incorrect origin from th ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2018-5113

The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5113

The "browser.identity.launchWebAuthFlow" function of WebExtensions is ...

CVSS3: 7.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5112

Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5112

Development Tools panels of an extension are required to load URLs for ...

CVSS3: 7.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5111

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.

CVSS3: 6.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5111

When the text of a specially formatted URL is dragged to the addressba ...

CVSS3: 6.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5110

If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible within Firefox. Note: This vulnerability only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 58.

CVSS3: 5.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5110

If cursor visibility is toggled by script using from 'none' to an imag ...

CVSS3: 5.3
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2018-5109

An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.

CVSS3: 5.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2018-5109

An audio capture session can started under an incorrect origin from th ...

CVSS3: 5.3
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться