Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2015-4517

почти 11 лет назад

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4516

почти 11 лет назад

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2015-4516

почти 11 лет назад

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2015-4512

почти 11 лет назад

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux ...

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2015-4512

почти 11 лет назад

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2015-4511

почти 11 лет назад

Heap-based buffer overflow in the nestegg_track_codec_data function in ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-4511

почти 11 лет назад

Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-4510

почти 11 лет назад

Race condition in the WorkerPrivate::NotifyFeatures function in Mozill ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-4510

почти 11 лет назад

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-4509

почти 11 лет назад

Use-after-free vulnerability in the HTMLVideoElement interface in Mozi ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4517

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

CVSS2: 7.5
3%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4516

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ...

CVSS2: 9.3
3%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-4516

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

CVSS2: 9.3
3%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4512

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux ...

CVSS2: 6.4
3%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-4512

gfx/2d/DataSurfaceHelpers.cpp in Mozilla Firefox before 41.0 on Linux improperly attempts to use the Cairo library with 32-bit color-depth surface creation followed by 16-bit color-depth surface display, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) by using a CANVAS element to trigger 2D rendering.

CVSS2: 6.4
3%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4511

Heap-based buffer overflow in the nestegg_track_codec_data function in ...

CVSS2: 6.8
5%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-4511

Heap-based buffer overflow in the nestegg_track_codec_data function in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allows remote attackers to execute arbitrary code via a crafted header in a WebM video.

CVSS2: 6.8
5%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4510

Race condition in the WorkerPrivate::NotifyFeatures function in Mozill ...

CVSS2: 6.8
3%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-4510

Race condition in the WorkerPrivate::NotifyFeatures function in Mozilla Firefox before 41.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and application crash) by leveraging improper interaction between shared workers and the IndexedDB implementation.

CVSS2: 6.8
3%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4509

Use-after-free vulnerability in the HTMLVideoElement interface in Mozi ...

CVSS2: 7.5
6%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться