Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2015-2743

около 11 лет назад

PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-2742

около 11 лет назад

Mozilla Firefox before 39.0 on OS X includes native key press informat ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2742

около 11 лет назад

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2741

около 11 лет назад

Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunder ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2741

около 11 лет назад

Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2740

около 11 лет назад

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2015-2740

около 11 лет назад

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2015-2739

около 11 лет назад

The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0 ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2015-2739

около 11 лет назад

The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2015-2738

около 11 лет назад

The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YC ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-2743

PDF.js in Mozilla Firefox before 39.0 and Firefox ESR 31.x before 31.8 and 38.x before 38.1 enables excessive privileges for internal Workers, which might allow remote attackers to execute arbitrary code by leveraging a Same Origin Policy bypass.

CVSS2: 7.5
5%
Низкий
около 11 лет назад
debian логотип
CVE-2015-2742

Mozilla Firefox before 39.0 on OS X includes native key press informat ...

CVSS2: 4.3
2%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-2742

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

CVSS2: 4.3
2%
Низкий
около 11 лет назад
debian логотип
CVE-2015-2741

Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunder ...

CVSS2: 4.3
1%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-2741

Mozilla Firefox before 39.0, Firefox ESR 38.x before 38.1, and Thunderbird before 38.1 do not enforce key pinning upon encountering an X.509 certificate problem that generates a user dialog, which allows user-assisted man-in-the-middle attackers to bypass intended access restrictions by triggering a (1) expired certificate or (2) mismatched hostname for a domain with pinning enabled.

CVSS2: 4.3
1%
Низкий
около 11 лет назад
debian логотип
CVE-2015-2740

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function ...

CVSS2: 10
6%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-2740

Buffer overflow in the nsXMLHttpRequest::AppendToResponseText function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 might allow remote attackers to cause a denial of service or have unspecified other impact via unknown vectors.

CVSS2: 10
6%
Низкий
около 11 лет назад
debian логотип
CVE-2015-2739

The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0 ...

CVSS2: 10
3%
Низкий
около 11 лет назад
nvd логотип
CVE-2015-2739

The ArrayBufferBuilder::append function in Mozilla Firefox before 39.0, Firefox ESR 31.x before 31.8 and 38.x before 38.1, and Thunderbird before 38.1 accesses unintended memory locations, which has unspecified impact and attack vectors.

CVSS2: 10
3%
Низкий
около 11 лет назад
debian логотип
CVE-2015-2738

The YCbCrImageDataDeserializer::ToDataSourceSurface function in the YC ...

CVSS2: 10
3%
Низкий
около 11 лет назад

Уязвимостей на страницу


Поделиться