Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

redhat логотип

CVE-2015-4502

почти 11 лет назад

js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-4476

почти 11 лет назад

Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-4500

почти 11 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2015-4507

почти 11 лет назад

The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2015-4504

почти 11 лет назад

The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.

CVSS2: 5.8
EPSS: Низкий
oracle-oval логотип

ELSA-2015-1699

почти 11 лет назад

ELSA-2015-1699: nss-softokn security update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-1694

почти 11 лет назад

ELSA-2015-1694: gdk-pixbuf2 security update (MODERATE)

EPSS: Низкий
debian логотип

CVE-2015-4498

почти 11 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and F ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4498

почти 11 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4497

почти 11 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implement ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2015-4502

js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.

CVSS2: 4.3
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-4476

Mozilla Firefox before 41.0 on Android allows user-assisted remote attackers to spoof address-bar attributes by leveraging lack of navigation after a paste of a URL with a nonstandard scheme, as demonstrated by spoofing an SSL attribute.

CVSS2: 5
2%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-4500

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 6.8
5%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-4507

The SavedStacks class in the JavaScript implementation in Mozilla Firefox before 41.0, when the Debugger API is enabled, allows remote attackers to cause a denial of service (getSlotRef assertion failure and application exit) or possibly execute arbitrary code via a crafted web site.

CVSS2: 5
3%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-4504

The lut_inverse_interp16 function in the QCMS library in Mozilla Firefox before 41.0 allows remote attackers to obtain sensitive information or cause a denial of service (buffer over-read and application crash) via crafted attributes in the ICC 4 profile of an image.

CVSS2: 5.8
3%
Низкий
почти 11 лет назад
oracle-oval логотип
ELSA-2015-1699

ELSA-2015-1699: nss-softokn security update (MODERATE)

4%
Низкий
почти 11 лет назад
oracle-oval логотип
ELSA-2015-1694

ELSA-2015-1694: gdk-pixbuf2 security update (MODERATE)

8%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and F ...

CVSS2: 7.5
3%
Низкий
почти 11 лет назад
nvd логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
3%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implement ...

CVSS2: 10
8%
Низкий
почти 11 лет назад

Уязвимостей на страницу


Поделиться