Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 379

nvd логотип

CVE-2017-5393

около 8 лет назад

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5393

около 8 лет назад

The "mozAddonManager" allows for the installation of extensions from t ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2017-5392

около 8 лет назад

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5392

около 8 лет назад

Weak proxy objects have weak references on multiple threads when they ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5391

около 8 лет назад

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5391

около 8 лет назад

Special "about:" pages used by web content, such as RSS feeds, can loa ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5390

около 8 лет назад

The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2017-5390

около 8 лет назад

The JSON viewer in the Developer Tools uses insecure methods to create ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2017-5389

около 8 лет назад

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2017-5389

около 8 лет назад

WebExtensions could use the "mozAddonManager" API by modifying the CSP ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2017-5393

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5393

The "mozAddonManager" allows for the installation of extensions from t ...

CVSS3: 6.1
1%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5392

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 9.8
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5392

Weak proxy objects have weak references on multiple threads when they ...

CVSS3: 9.8
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5391

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.

CVSS3: 9.8
2%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5391

Special "about:" pages used by web content, such as RSS feeds, can loa ...

CVSS3: 9.8
2%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5390

The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.

CVSS3: 9.8
4%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5390

The JSON viewer in the Developer Tools uses insecure methods to create ...

CVSS3: 9.8
4%
Низкий
около 8 лет назад
nvd логотип
CVE-2017-5389

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
1%
Низкий
около 8 лет назад
debian логотип
CVE-2017-5389

WebExtensions could use the "mozAddonManager" API by modifying the CSP ...

CVSS3: 6.1
1%
Низкий
около 8 лет назад

Уязвимостей на страницу


Поделиться