Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 368

debian логотип

CVE-2017-5430

около 8 лет назад

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Th ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5429

около 8 лет назад

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5429

около 8 лет назад

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Fire ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5428

около 8 лет назад

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5428

около 8 лет назад

An integer overflow in "createImageBitmap()" was reported through the ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5427

около 8 лет назад

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2017-5427

около 8 лет назад

A non-existent chrome.manifest file will attempt to be loaded during s ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2017-5426

около 8 лет назад

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. Note: this issue only affects Linux. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-5426

около 8 лет назад

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is run ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-5425

около 8 лет назад

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-5430

Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Th ...

CVSS3: 9.8
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5429

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5429

Memory safety bugs were reported in Firefox 52, Firefox ESR 45.8, Fire ...

CVSS3: 9.8
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5428

An integer overflow in "createImageBitmap()" was reported through the Pwn2Own contest. The fix for this vulnerability disables the experimental extensions to the "createImageBitmap" API. This function runs in the content sandbox, requiring a second vulnerability to compromise a user's computer. This vulnerability affects Firefox ESR < 52.0.1 and Firefox < 52.0.1.

CVSS3: 9.8
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5428

An integer overflow in "createImageBitmap()" was reported through the ...

CVSS3: 9.8
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5427

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

CVSS3: 5.5
0%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5427

A non-existent chrome.manifest file will attempt to be loaded during s ...

CVSS3: 5.5
0%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5426

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is running when the Gecko Media Plugin sandbox is started, the sandbox fails to be applied and items that would run within the sandbox are run protected only by the running filter which is typically weak compared to the sandbox. Note: this issue only affects Linux. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 5.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5426

On Linux, if the secure computing mode BPF (seccomp-bpf) filter is run ...

CVSS3: 5.3
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5425

The Gecko Media Plugin sandbox allows access to local files that match specific regular expressions. On OS OX, this matching allows access to some data in subdirectories of "/private/var" that could expose personal or temporary data. This has been updated to not allow access to "/private/var" and its subdirectories. Note: this issue only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
2%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться