Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2015-4497

почти 11 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2015-4497

почти 11 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2015-4498

почти 11 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
EPSS: Низкий
fstec логотип

BDU:2015-11311

почти 11 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
EPSS: Низкий
fstec логотип

BDU:2015-11312

почти 11 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю обойти процедуру подтверждения действий пользователем при установке обновления

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2015-4498

почти 11 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2015-4497

почти 11 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-4496

около 11 лет назад

Multiple integer overflows in libstagefright in Mozilla Firefox before ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2015-4496

около 11 лет назад

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2015-4493

около 11 лет назад

Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
8%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
8%
Низкий
почти 11 лет назад
ubuntu логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
3%
Низкий
почти 11 лет назад
fstec логотип
BDU:2015-11311

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
8%
Низкий
почти 11 лет назад
fstec логотип
BDU:2015-11312

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю обойти процедуру подтверждения действий пользователем при установке обновления

CVSS2: 7.5
3%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 5.1
3%
Низкий
почти 11 лет назад
redhat логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 6.8
8%
Низкий
почти 11 лет назад
debian логотип
CVE-2015-4496

Multiple integer overflows in libstagefright in Mozilla Firefox before ...

CVSS2: 9.3
4%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4496

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.

CVSS2: 9.3
4%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4493

Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor ...

CVSS2: 9.3
7%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться