Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

ubuntu логотип

CVE-2016-7153

почти 10 лет назад

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
ubuntu логотип

CVE-2016-7152

почти 10 лет назад

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
EPSS: Средний
oracle-oval логотип

ELSA-2016-1809

почти 10 лет назад

ELSA-2016-1809: thunderbird security update (IMPORTANT)

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2016:2209-1

почти 10 лет назад

Security update for libtcnative-1-0

EPSS: Критический
debian логотип

CVE-2016-5268

около 10 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-5268

около 10 лет назад

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-5267

около 10 лет назад

Mozilla Firefox before 48.0 on Android allows remote attackers to spoo ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2016-5267

около 10 лет назад

Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2016-5266

около 10 лет назад

Mozilla Firefox before 48.0 does not properly restrict drag-and-drop ( ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2016-5266

около 10 лет назад

Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2016-7153

The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
14%
Средний
почти 10 лет назад
ubuntu логотип
CVE-2016-7152

The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.

CVSS3: 5.3
14%
Средний
почти 10 лет назад
oracle-oval логотип
ELSA-2016-1809

ELSA-2016-1809: thunderbird security update (IMPORTANT)

3%
Низкий
почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2016:2209-1

Security update for libtcnative-1-0

100%
Критический
почти 10 лет назад
debian логотип
CVE-2016-5268

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI ...

CVSS3: 4.3
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5268

Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.

CVSS3: 4.3
1%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5267

Mozilla Firefox before 48.0 on Android allows remote attackers to spoo ...

CVSS3: 5.3
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5267

Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set.

CVSS3: 5.3
1%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5266

Mozilla Firefox before 48.0 does not properly restrict drag-and-drop ( ...

CVSS3: 8.1
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5266

Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site.

CVSS3: 8.1
2%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться