Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 368

debian логотип

CVE-2017-5408

около 8 лет назад

Video files loaded video captions cross-origin without checking for th ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-5407

около 8 лет назад

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2017-5407

около 8 лет назад

Using SVG filters that don't use the fixed point math implementation o ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2017-5406

около 8 лет назад

A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2017-5406

около 8 лет назад

A segmentation fault can occur in the Skia graphics library during som ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2017-5405

около 8 лет назад

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2017-5405

около 8 лет назад

Certain response codes in FTP connections can result in the use of uni ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2017-5404

около 8 лет назад

A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2017-5404

около 8 лет назад

A use-after-free error can occur when manipulating ranges in selection ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2017-5403

около 8 лет назад

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-5408

Video files loaded video captions cross-origin without checking for th ...

CVSS3: 5.3
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5407

Using SVG filters that don't use the fixed point math implementation o ...

CVSS3: 6.5
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5406

A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5406

A segmentation fault can occur in the Skia graphics library during som ...

CVSS3: 7.5
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5405

Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 5.3
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5405

Certain response codes in FTP connections can result in the use of uni ...

CVSS3: 5.3
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5404

A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 9.8
17%
Средний
около 8 лет назад
debian логотип
CVE-2017-5404

A use-after-free error can occur when manipulating ranges in selection ...

CVSS3: 9.8
17%
Средний
около 8 лет назад
nvd логотип
CVE-2017-5403

When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 9.8
2%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться