Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

redhat логотип

CVE-2016-9075

почти 10 лет назад

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2023-01952

почти 10 лет назад

Уязвимость плагина NPAPI браузера Firefox операционных систем Windows, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2016-5287

почти 10 лет назад

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2016-5288

почти 10 лет назад

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 5.3
EPSS: Низкий
oracle-oval логотип

ELSA-2016-1985

почти 10 лет назад

ELSA-2016-1985: thunderbird security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2385-1

почти 10 лет назад

Security update for libtcnative-1-0

EPSS: Критический
debian логотип

CVE-2016-5284

почти 10 лет назад

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunder ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2016-5284

почти 10 лет назад

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2016-5283

почти 10 лет назад

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-5283

почти 10 лет назад

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2016-9075

An issue where WebExtensions can use the mozAddonManager API to elevate privilege due to privileged pages being allowed in the permissions list. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 50.

CVSS3: 9.8
2%
Низкий
почти 10 лет назад
fstec логотип
BDU:2023-01952

Уязвимость плагина NPAPI браузера Firefox операционных систем Windows, позволяющая нарушителю обойти ограничения безопасности

CVSS3: 7.5
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-5287

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 9.8
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-5288

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 5.3
2%
Низкий
почти 10 лет назад
oracle-oval логотип
ELSA-2016-1985

ELSA-2016-1985: thunderbird security update (IMPORTANT)

4%
Низкий
почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2385-1

Security update for libtcnative-1-0

100%
Критический
почти 10 лет назад
debian логотип
CVE-2016-5284

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunder ...

CVSS3: 7.4
2%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-5284

Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 rely on unintended expiration dates for Preloaded Public Key Pinning, which allows man-in-the-middle attackers to spoof add-on updates by leveraging possession of an X.509 server certificate for addons.mozilla.org signed by an arbitrary built-in Certification Authority.

CVSS3: 7.4
2%
Низкий
почти 10 лет назад
debian логотип
CVE-2016-5283

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same ...

CVSS3: 8.8
1%
Низкий
почти 10 лет назад
nvd логотип
CVE-2016-5283

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

CVSS3: 8.8
1%
Низкий
почти 10 лет назад

Уязвимостей на страницу


Поделиться