Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2016-1967

больше 10 лет назад

Mozilla Firefox before 45.0 does not properly restrict the availabilit ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2016-1967

больше 10 лет назад

Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2016-1966

больше 10 лет назад

The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRu ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-1966

больше 10 лет назад

The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference and memory corruption) via a crafted NPAPI plugin.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-1965

больше 10 лет назад

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-1965

больше 10 лет назад

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-1964

больше 10 лет назад

Use-after-free vulnerability in the AtomicBaseIncDec function in Mozil ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-1964

больше 10 лет назад

Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-1963

больше 10 лет назад

The FileReader class in Mozilla Firefox before 45.0 allows local users ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2016-1963

больше 10 лет назад

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-1967

Mozilla Firefox before 45.0 does not properly restrict the availabilit ...

CVSS3: 6.5
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1967

Mozilla Firefox before 45.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls after restoring a browser session. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7207.

CVSS3: 6.5
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-1966

The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRu ...

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1966

The nsNPObjWrapper::GetNewOrUsed function in dom/plugins/base/nsJSNPRuntime.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer dereference and memory corruption) via a crafted NPAPI plugin.

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-1965

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle ...

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1965

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-1964

Use-after-free vulnerability in the AtomicBaseIncDec function in Mozil ...

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1964

Use-after-free vulnerability in the AtomicBaseIncDec function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging mishandling of XML transformations.

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-1963

The FileReader class in Mozilla Firefox before 45.0 allows local users ...

CVSS3: 7.4
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1963

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
0%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться