Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 368

debian логотип

CVE-2017-5458

около 8 лет назад

When a "javascript:" URL is drag and dropped by a user into the addres ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5456

около 8 лет назад

A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5456

около 8 лет назад

A mechanism to bypass file system access protections in the sandbox us ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5455

около 8 лет назад

The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vulnerability that resulted in remote code execution inside the sandboxed process. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-5455

около 8 лет назад

The internal feed reader APIs that crossed the sandbox barrier allowed ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-5454

около 8 лет назад

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-5454

около 8 лет назад

A mechanism to bypass file system access protections in the sandbox to ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-5453

около 8 лет назад

A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. This vulnerability allows for spoofing but no scripted content can be run. This vulnerability affects Firefox < 53.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2017-5453

около 8 лет назад

A mechanism to inject static HTML into the RSS reader preview page due ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2017-5452

около 8 лет назад

Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-5458

When a "javascript:" URL is drag and dropped by a user into the addres ...

CVSS3: 6.1
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5456

A mechanism to bypass file system access protections in the sandbox using the file system request constructor through an IPC message. This allows for read and write access to the local file system. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.

CVSS3: 9.8
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5456

A mechanism to bypass file system access protections in the sandbox us ...

CVSS3: 9.8
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5455

The internal feed reader APIs that crossed the sandbox barrier allowed for a sandbox escape and escalation of privilege if combined with another vulnerability that resulted in remote code execution inside the sandboxed process. This vulnerability affects Firefox ESR < 52.1 and Firefox < 53.

CVSS3: 7.5
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5455

The internal feed reader APIs that crossed the sandbox barrier allowed ...

CVSS3: 7.5
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5454

A mechanism to bypass file system access protections in the sandbox to use the file picker to access different files than those selected in the file picker through the use of relative paths. This allows for read only access to the local file system. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5454

A mechanism to bypass file system access protections in the sandbox to ...

CVSS3: 7.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5453

A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. This vulnerability allows for spoofing but no scripted content can be run. This vulnerability affects Firefox < 53.

CVSS3: 4.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5453

A mechanism to inject static HTML into the RSS reader preview page due ...

CVSS3: 4.3
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5452

Malicious sites can display a spoofed addressbar on a page when the existing location bar on the new page is scrolled out of view if an HTML editable page element is user selected. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.

CVSS3: 4.3
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться