Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2015-7186

почти 11 лет назад

Mozilla Firefox before 42.0 on Android allows user-assisted remote att ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-7186

почти 11 лет назад

Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-7185

почти 11 лет назад

Mozilla Firefox before 42.0 on Android does not ensure that the addres ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-7185

почти 11 лет назад

Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-7183

почти 11 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape P ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-7183

почти 11 лет назад

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-7182

почти 11 лет назад

Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Sec ...

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2015-7182

почти 11 лет назад

Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2015-7181

почти 11 лет назад

The sec_asn1d_parse_leaf function in Mozilla Network Security Services ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-7181

почти 11 лет назад

The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-7186

Mozilla Firefox before 42.0 on Android allows user-assisted remote att ...

CVSS2: 4.3
2%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7186

Mozilla Firefox before 42.0 on Android allows user-assisted remote attackers to bypass the Same Origin Policy and trigger (1) a download or (2) cached profile-data reading via a file: URL in a saved HTML document.

CVSS2: 4.3
2%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-7185

Mozilla Firefox before 42.0 on Android does not ensure that the addres ...

CVSS2: 4.3
1%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7185

Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

CVSS2: 4.3
1%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-7183

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape P ...

CVSS2: 7.5
7%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7183

Integer overflow in the PL_ARENA_ALLOCATE implementation in Netscape Portable Runtime (NSPR) in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via unspecified vectors.

CVSS2: 7.5
7%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-7182

Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Sec ...

CVSS3: 9.8
10%
Средний
почти 11 лет назад
nvd логотип
CVE-2015-7182

Heap-based buffer overflow in the ASN.1 decoder in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data.

CVSS3: 9.8
10%
Средний
почти 11 лет назад
debian логотип
CVE-2015-7181

The sec_asn1d_parse_leaf function in Mozilla Network Security Services ...

CVSS2: 7.5
8%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-7181

The sec_asn1d_parse_leaf function in Mozilla Network Security Services (NSS) before 3.19.2.1 and 3.20.x before 3.20.1, as used in Firefox before 42.0 and Firefox ESR 38.x before 38.4 and other products, improperly restricts access to an unspecified data structure, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OCTET STRING data, related to a "use-after-poison" issue.

CVSS2: 7.5
8%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться