Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 368

debian логотип

CVE-2017-7809

около 8 лет назад

A use-after-free vulnerability can occur when an editor DOM node is de ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-7808

около 8 лет назад

A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-7808

около 8 лет назад

A content security policy (CSP) "frame-ancestors" directive containing ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-7807

около 8 лет назад

A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2017-7807

около 8 лет назад

A mechanism that uses AppCache to hijack a URL in a domain using fallb ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2017-7806

около 8 лет назад

A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-7806

около 8 лет назад

A use-after-free vulnerability can occur when the layer manager is fre ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7805

около 8 лет назад

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-7805

около 8 лет назад

During TLS 1.2 exchanges, handshake hashes are generated which point t ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-7804

около 8 лет назад

The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memory protections in this situation. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-7809

A use-after-free vulnerability can occur when an editor DOM node is de ...

CVSS3: 9.8
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7808

A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.

CVSS3: 5.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7808

A content security policy (CSP) "frame-ancestors" directive containing ...

CVSS3: 5.3
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7807

A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

CVSS3: 8.1
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7807

A mechanism that uses AppCache to hijack a URL in a domain using fallb ...

CVSS3: 8.1
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7806

A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7806

A use-after-free vulnerability can occur when the layer manager is fre ...

CVSS3: 7.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.

CVSS3: 7.5
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7805

During TLS 1.2 exchanges, handshake hashes are generated which point t ...

CVSS3: 7.5
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7804

The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memory protections in this situation. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.

CVSS3: 7.5
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться