Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2015-4000

около 11 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
EPSS: Критический
ubuntu логотип

CVE-2015-4000

около 11 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
EPSS: Критический
redhat логотип

CVE-2015-4000

около 11 лет назад

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
EPSS: Критический
debian логотип

CVE-2015-2720

больше 11 лет назад

The update implementation in Mozilla Firefox before 38.0 on Windows do ...

CVSS2: 4.4
EPSS: Низкий
nvd логотип

CVE-2015-2720

больше 11 лет назад

The update implementation in Mozilla Firefox before 38.0 on Windows does not ensure that the pathname for updater.exe corresponds to the application directory, which might allow local users to gain privileges via a Trojan horse file.

CVSS2: 4.4
EPSS: Низкий
debian логотип

CVE-2015-2718

больше 11 лет назад

The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-2718

больше 11 лет назад

The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive webchannel-response data via a crafted web site containing an IFRAME element referencing a different web site that is intended to read this data.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-2717

больше 11 лет назад

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allo ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2717

больше 11 лет назад

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and out-of-bounds read) via an MP4 video file containing invalid metadata.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2716

больше 11 лет назад

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Fire ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
100%
Критический
около 11 лет назад
ubuntu логотип
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
100%
Критический
около 11 лет назад
redhat логотип
CVE-2015-4000

The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a ServerHello with DHE_EXPORT replaced by DHE, aka the "Logjam" issue.

CVSS3: 3.7
100%
Критический
около 11 лет назад
debian логотип
CVE-2015-2720

The update implementation in Mozilla Firefox before 38.0 on Windows do ...

CVSS2: 4.4
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2720

The update implementation in Mozilla Firefox before 38.0 on Windows does not ensure that the pathname for updater.exe corresponds to the application directory, which might allow local users to gain privileges via a Trojan horse file.

CVSS2: 4.4
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2718

The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote ...

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2718

The WebChannel.jsm module in Mozilla Firefox before 38.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive webchannel-response data via a crafted web site containing an IFRAME element referencing a different web site that is intended to read this data.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2717

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allo ...

CVSS2: 6.8
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2717

Integer overflow in libstagefright in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and out-of-bounds read) via an MP4 video file containing invalid metadata.

CVSS2: 6.8
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2716

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Fire ...

CVSS2: 7.5
7%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться