Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2016-1962

больше 10 лет назад

Use-after-free vulnerability in the mozilla::DataChannelConnection::Cl ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2016-1962

больше 10 лет назад

Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2016-1961

больше 10 лет назад

Use-after-free vulnerability in the nsHTMLDocument::SetBody function i ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-1961

больше 10 лет назад

Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-1960

больше 10 лет назад

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string ...

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2016-1960

больше 10 лет назад

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2016-1959

больше 10 лет назад

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows r ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2016-1959

больше 10 лет назад

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2016-1958

больше 10 лет назад

browser/base/content/browser.js in Mozilla Firefox before 45.0 and Fir ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-1958

больше 10 лет назад

browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2016-1962

Use-after-free vulnerability in the mozilla::DataChannelConnection::Cl ...

CVSS3: 9.8
6%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1962

Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.

CVSS3: 9.8
6%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-1961

Use-after-free vulnerability in the nsHTMLDocument::SetBody function i ...

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1961

Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-1960

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string ...

CVSS3: 8.8
31%
Средний
больше 10 лет назад
nvd логотип
CVE-2016-1960

Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.

CVSS3: 8.8
31%
Средний
больше 10 лет назад
debian логотип
CVE-2016-1959

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows r ...

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1959

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.

CVSS3: 8.8
3%
Низкий
больше 10 лет назад
debian логотип
CVE-2016-1958

browser/base/content/browser.js in Mozilla Firefox before 45.0 and Fir ...

CVSS3: 4.3
2%
Низкий
больше 10 лет назад
nvd логотип
CVE-2016-1958

browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.

CVSS3: 4.3
2%
Низкий
больше 10 лет назад

Уязвимостей на страницу


Поделиться