Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

redhat логотип

CVE-2016-5278

почти 10 лет назад

Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2016-5272

почти 10 лет назад

The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arbitrary code via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2016-5283

почти 10 лет назад

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2016-5273

почти 10 лет назад

The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2016-5277

почти 10 лет назад

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2016:2267-1

почти 10 лет назад

Security update for libtcnative-1-0

EPSS: Критический
debian логотип

CVE-2016-7153

почти 10 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion w ...

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2016-7153

почти 10 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2016-7152

почти 10 лет назад

The HTTPS protocol does not consider the role of the TCP congestion wi ...

CVSS3: 5.3
EPSS: Средний
nvd логотип

CVE-2016-7152

почти 10 лет назад

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2016-5278

Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.

CVSS3: 8.8
4%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-5272

The nsImageGeometryMixin class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 does not properly perform a cast of an unspecified variable during handling of INPUT elements, which allows remote attackers to execute arbitrary code via a crafted web site.

CVSS3: 8.8
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-5283

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

CVSS3: 8.8
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-5273

The mozilla::a11y::HyperTextAccessible::GetChildOffset function in the accessibility implementation in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code via a crafted web site.

CVSS3: 8.8
2%
Низкий
почти 10 лет назад
redhat логотип
CVE-2016-5277

Use-after-free vulnerability in the nsRefreshDriver::Tick function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging improper interaction between timeline destruction and the Web Animations model implementation.

CVSS3: 9.8
4%
Низкий
почти 10 лет назад
suse-cvrf логотип
openSUSE-SU-2016:2267-1

Security update for libtcnative-1-0

100%
Критический
почти 10 лет назад
debian логотип
CVE-2016-7153

The HTTP/2 protocol does not consider the role of the TCP congestion w ...

CVSS3: 5.3
14%
Средний
почти 10 лет назад
nvd логотип
CVE-2016-7153

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
14%
Средний
почти 10 лет назад
debian логотип
CVE-2016-7152

The HTTPS protocol does not consider the role of the TCP congestion wi ...

CVSS3: 5.3
14%
Средний
почти 10 лет назад
nvd логотип
CVE-2016-7152

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
14%
Средний
почти 10 лет назад

Уязвимостей на страницу


Поделиться