Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 368

debian логотип

CVE-2017-7778

около 8 лет назад

A number of security vulnerabilities in the Graphite 2 library includi ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-7770

около 8 лет назад

A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing the location of an arbitrary website instead of the one loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox < 54.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2017-7770

около 8 лет назад

A mechanism where when a new tab is loaded through JavaScript events, ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2017-7768

около 8 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2017-7768

около 8 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2017-7767

около 8 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2017-7767

около 8 лет назад

The Mozilla Maintenance Service can be invoked by an unprivileged user ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2017-7766

около 8 лет назад

An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2017-7766

около 8 лет назад

An attack using manipulation of "updater.ini" contents, used by the Mo ...

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2017-7765

около 8 лет назад

The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows displays before running executables downloaded from the Internet is not shown. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-7778

A number of security vulnerabilities in the Graphite 2 library includi ...

CVSS3: 9.8
5%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7770

A mechanism where when a new tab is loaded through JavaScript events, if fullscreen mode is then entered, the addressbar will not be rendered. This would allow a malicious site to displayed a spoofed addressbar, showing the location of an arbitrary website instead of the one loaded. Note: this issue only affects Firefox for Android. Desktop Firefox is unaffected. This vulnerability affects Firefox < 54.

CVSS3: 5.9
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7770

A mechanism where when a new tab is loaded through JavaScript events, ...

CVSS3: 5.9
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user to read 32 bytes of any arbitrary file on the local system by convincing the service that it is reading a status file provided by the Mozilla Windows Updater. The Mozilla Maintenance Service executes with privileged access, bypassing system protections against unprivileged users. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7768

The Mozilla Maintenance Service can be invoked by an unprivileged user ...

CVSS3: 5.5
0%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7767

The Mozilla Maintenance Service can be invoked by an unprivileged user to overwrite arbitrary files with junk data using the Mozilla Windows Updater, which runs with the Maintenance Service's privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7767

The Mozilla Maintenance Service can be invoked by an unprivileged user ...

CVSS3: 5.5
0%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7766

An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 7.8
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-7766

An attack using manipulation of "updater.ini" contents, used by the Mo ...

CVSS3: 7.8
0%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-7765

The "Mark of the Web" was not correctly saved on Windows when files with very long names were downloaded from the Internet. Without the Mark of the Web data, the security warning that Windows displays before running executables downloaded from the Internet is not shown. Note: This attack only affects Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 54, Firefox ESR < 52.2, and Thunderbird < 52.2.

CVSS3: 7.5
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться