Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2016-5260

около 10 лет назад

Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="passw ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-5260

около 10 лет назад

Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-5259

около 10 лет назад

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant funct ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-5259

около 10 лет назад

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-5258

около 10 лет назад

Use-after-free vulnerability in the WebRTC socket thread in Mozilla Fi ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-5258

около 10 лет назад

Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-5255

около 10 лет назад

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-5255

около 10 лет назад

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-5254

около 10 лет назад

Use-after-free vulnerability in the nsXULPopupManager::KeyDown functio ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-5254

около 10 лет назад

Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) by leveraging keyboard access to use the Alt key during selection of top-level menu items.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-5260

Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="passw ...

CVSS3: 6.5
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5260

Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.

CVSS3: 6.5
1%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5259

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant funct ...

CVSS3: 8.8
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5259

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.

CVSS3: 8.8
3%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5258

Use-after-free vulnerability in the WebRTC socket thread in Mozilla Fi ...

CVSS3: 8.8
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5258

Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session.

CVSS3: 8.8
3%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5255

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep ...

CVSS3: 8.8
2%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5255

Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.

CVSS3: 8.8
2%
Низкий
около 10 лет назад
debian логотип
CVE-2016-5254

Use-after-free vulnerability in the nsXULPopupManager::KeyDown functio ...

CVSS3: 9.8
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2016-5254

Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) by leveraging keyboard access to use the Alt key during selection of top-level menu items.

CVSS3: 9.8
3%
Низкий
около 10 лет назад

Уязвимостей на страницу


Поделиться