Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2015-4478

около 11 лет назад

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-4477

около 11 лет назад

Use-after-free vulnerability in the MediaStream playback feature in Mo ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2015-4477

около 11 лет назад

Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2015-4475

около 11 лет назад

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Fir ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-4475

около 11 лет назад

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4474

около 11 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2015-4474

около 11 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2015-4473

около 11 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2015-4473

около 11 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2015-4489

около 11 лет назад

The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4478

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.

CVSS2: 5
3%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4477

Use-after-free vulnerability in the MediaStream playback feature in Mo ...

CVSS2: 10
6%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4477

Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.

CVSS2: 10
6%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4475

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Fir ...

CVSS2: 7.5
5%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4475

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.

CVSS2: 7.5
5%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4474

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
6%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4474

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
6%
Низкий
около 11 лет назад
debian логотип
CVE-2015-4473

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
7%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-4473

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
7%
Низкий
около 11 лет назад
ubuntu логотип
CVE-2015-4489

The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.

CVSS2: 7.5
4%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться