Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

suse-cvrf логотип

SUSE-SU-2015:1526-1

около 11 лет назад

Security update for gnutls

EPSS: Критический
suse-cvrf логотип

SUSE-SU-2015:1380-1

около 11 лет назад

Security update for MozillaFirefox

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2015:1379-1

около 11 лет назад

Security update for MozillaFirefox

EPSS: Средний
redhat логотип

CVE-2015-4496

около 11 лет назад

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.

CVSS2: 6.8
EPSS: Низкий
fstec логотип

BDU:2015-11141

около 11 лет назад

Уязвимости браузера Firefox, позволяющие нарушителю выполнить произвольный код

CVSS2: 9.3
EPSS: Низкий
redhat логотип

CVE-2015-4479

около 11 лет назад

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2015-4492

около 11 лет назад

Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2015-4484

около 11 лет назад

The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-4489

около 11 лет назад

The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2015-4475

около 11 лет назад

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
SUSE-SU-2015:1526-1

Security update for gnutls

100%
Критический
около 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:1380-1

Security update for MozillaFirefox

69%
Средний
около 11 лет назад
suse-cvrf логотип
SUSE-SU-2015:1379-1

Security update for MozillaFirefox

69%
Средний
около 11 лет назад
redhat логотип
CVE-2015-4496

Multiple integer overflows in libstagefright in Mozilla Firefox before 38.0 allow remote attackers to execute arbitrary code via crafted sample metadata in an MPEG-4 video file, a related issue to CVE-2015-1538.

CVSS2: 6.8
4%
Низкий
около 11 лет назад
fstec логотип
BDU:2015-11141

Уязвимости браузера Firefox, позволяющие нарушителю выполнить произвольный код

CVSS2: 9.3
4%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-4479

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.

CVSS2: 6.8
9%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-4492

Use-after-free vulnerability in the XMLHttpRequest::Open implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 might allow remote attackers to execute arbitrary code via a SharedWorker object that makes recursive calls to the open method of an XMLHttpRequest object.

CVSS2: 5.1
5%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-4484

The js::jit::AssemblerX86Shared::lock_addl function in the JavaScript implementation in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to cause a denial of service (application crash) by leveraging the use of shared memory and accessing (1) an Atomics object or (2) a SharedArrayBuffer object.

CVSS2: 4.3
4%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-4489

The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.

CVSS2: 5.1
4%
Низкий
около 11 лет назад
redhat логотип
CVE-2015-4475

The mozilla::AudioSink function in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 mishandles inconsistent sample formats within MP3 audio data, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via a malformed file.

CVSS2: 5.1
5%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться