Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2015-4483

около 11 лет назад

Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-4482

около 11 лет назад

mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox E ...

CVSS2: 4.6
EPSS: Низкий
nvd логотип

CVE-2015-4482

около 11 лет назад

mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (aka MAR) file.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2015-4481

около 11 лет назад

Race condition in the Mozilla Maintenance Service in Mozilla Firefox b ...

CVSS2: 3.3
EPSS: Низкий
nvd логотип

CVE-2015-4481

около 11 лет назад

Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.

CVSS2: 3.3
EPSS: Низкий
debian логотип

CVE-2015-4480

около 11 лет назад

Integer overflow in the stagefright::SampleTable::isValid function in ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2015-4480

около 11 лет назад

Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2015-4479

около 11 лет назад

Multiple integer overflows in libstagefright in Mozilla Firefox before ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2015-4479

около 11 лет назад

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2015-4478

около 11 лет назад

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not im ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4483

Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.

CVSS2: 4.3
2%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4482

mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox E ...

CVSS2: 4.6
0%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4482

mar_read.c in the Updater in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows local users to gain privileges or cause a denial of service (out-of-bounds write) via a crafted name of a Mozilla Archive (aka MAR) file.

CVSS2: 4.6
0%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4481

Race condition in the Mozilla Maintenance Service in Mozilla Firefox b ...

CVSS2: 3.3
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4481

Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.

CVSS2: 3.3
1%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4480

Integer overflow in the stagefright::SampleTable::isValid function in ...

CVSS2: 9.3
6%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4480

Integer overflow in the stagefright::SampleTable::isValid function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via crafted MPEG-4 video data with H.264 encoding.

CVSS2: 9.3
6%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4479

Multiple integer overflows in libstagefright in Mozilla Firefox before ...

CVSS2: 10
9%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4479

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.

CVSS2: 10
9%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4478

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not im ...

CVSS2: 5
3%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться