Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 368

debian логотип

CVE-2017-5398

около 8 лет назад

Memory safety bugs were reported in Thunderbird 45.7. Some of these bu ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5397

около 8 лет назад

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5397

около 8 лет назад

The cache directory on the local file system is set to be world writab ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5396

около 8 лет назад

A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5396

около 8 лет назад

A use-after-free vulnerability in the Media Decoder when working with ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5395

около 8 лет назад

Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2017-5395

около 8 лет назад

Malicious sites can display a spoofed location bar on a subsequently l ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2017-5394

около 8 лет назад

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-5394

около 8 лет назад

A location bar spoofing attack where the location bar of loaded page w ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2017-5393

около 8 лет назад

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2017-5398

Memory safety bugs were reported in Thunderbird 45.7. Some of these bu ...

CVSS3: 9.8
4%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5397

The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.

CVSS3: 9.8
3%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5397

The cache directory on the local file system is set to be world writab ...

CVSS3: 9.8
3%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5396

A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVSS3: 9.8
4%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5396

A use-after-free vulnerability in the Media Decoder when working with ...

CVSS3: 9.8
4%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5395

Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 4.3
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5395

Malicious sites can display a spoofed location bar on a subsequently l ...

CVSS3: 4.3
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5394

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 8.8
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5394

A location bar spoofing attack where the location bar of loaded page w ...

CVSS3: 8.8
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5393

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.

CVSS3: 6.1
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться