Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2015-7191

почти 11 лет назад

Mozilla Firefox before 42.0 on Android improperly restricts URL string ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-7191

почти 11 лет назад

Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-7190

почти 11 лет назад

The Search feature in Mozilla Firefox before 42.0 on Android through 4 ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2015-7190

почти 11 лет назад

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-7189

почти 11 лет назад

Race condition in the JPEGEncoder function in Mozilla Firefox before 4 ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-7189

почти 11 лет назад

Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-7188

почти 11 лет назад

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow rem ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-7188

почти 11 лет назад

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-7187

почти 11 лет назад

The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-7187

почти 11 лет назад

The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-7191

Mozilla Firefox before 42.0 on Android improperly restricts URL string ...

CVSS2: 4.3
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7191

Mozilla Firefox before 42.0 on Android improperly restricts URL strings in intents, which allows attackers to conduct cross-site scripting (XSS) attacks via vectors involving an intent: URL and fallback navigation, aka "Universal XSS (UXSS)."

CVSS2: 4.3
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-7190

The Search feature in Mozilla Firefox before 42.0 on Android through 4 ...

CVSS2: 5
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7190

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.

CVSS2: 5
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-7189

Race condition in the JPEGEncoder function in Mozilla Firefox before 4 ...

CVSS2: 6.8
3%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7189

Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.

CVSS2: 6.8
3%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-7188

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow rem ...

CVSS2: 7.5
3%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7188

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allow remote attackers to bypass the Same Origin Policy for an IP address origin, and conduct cross-site scripting (XSS) attacks, by appending whitespace characters to an IP address string.

CVSS2: 7.5
3%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-7187

The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: ...

CVSS2: 4.3
2%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7187

The Add-on SDK in Mozilla Firefox before 42.0 misinterprets a "script: false" panel setting, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via inline JavaScript code that is executed within a third-party extension.

CVSS2: 4.3
2%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться