Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 368

debian логотип

CVE-2017-5469

около 8 лет назад

Fixed potential buffer overflows in generated Firefox code due to CVE- ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5468

около 8 лет назад

An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2017-5468

около 8 лет назад

An issue with incorrect ownership model of "privateBrowsing" informati ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2017-5467

около 8 лет назад

A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-5467

около 8 лет назад

A potential memory corruption and crash when using Skia content when d ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-5466

около 8 лет назад

If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5466

около 8 лет назад

If a page is loaded from an original site through a hyperlink and cont ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5465

около 8 лет назад

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.1
EPSS: Средний
debian логотип

CVE-2017-5465

около 8 лет назад

An out-of-bounds read while processing SVG content in "ConvolvePixel". ...

CVSS3: 9.1
EPSS: Средний
nvd логотип

CVE-2017-5464

около 8 лет назад

During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-5469

Fixed potential buffer overflows in generated Firefox code due to CVE- ...

CVSS3: 9.8
5%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5468

An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.

CVSS3: 9.1
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5468

An issue with incorrect ownership model of "privateBrowsing" informati ...

CVSS3: 9.1
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5467

A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5467

A potential memory corruption and crash when using Skia content when d ...

CVSS3: 7.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5466

If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 6.1
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5466

If a page is loaded from an original site through a hyperlink and cont ...

CVSS3: 6.1
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5465

An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.1
19%
Средний
около 8 лет назад
debian логотип
CVE-2017-5465

An out-of-bounds read while processing SVG content in "ConvolvePixel". ...

CVSS3: 9.1
19%
Средний
около 8 лет назад
nvd логотип
CVE-2017-5464

During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
3%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться