Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2015-2716

больше 11 лет назад

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-2715

больше 11 лет назад

Race condition in the nsThreadManager::RegisterCurrentThread function ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2715

больше 11 лет назад

Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) by leveraging improper Media Decoder Thread creation at the time of a shutdown.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2714

больше 11 лет назад

Mozilla Firefox before 38.0 on Android does not properly restrict writ ...

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2015-2714

больше 11 лет назад

Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2015-2713

больше 11 лет назад

Use-after-free vulnerability in the SetBreaks function in Mozilla Fire ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-2713

больше 11 лет назад

Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-2712

больше 11 лет назад

The asm.js implementation in Mozilla Firefox before 38.0 does not prop ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-2712

больше 11 лет назад

The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote attackers to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sensitive information from process memory, via crafted JavaScript.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-2711

больше 11 лет назад

Mozilla Firefox before 38.0 does not recognize a referrer policy deliv ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2015-2716

Buffer overflow in the XML parser in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code by providing a large amount of compressed XML data, a related issue to CVE-2015-1283.

CVSS2: 7.5
7%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2715

Race condition in the nsThreadManager::RegisterCurrentThread function ...

CVSS2: 6.8
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2715

Race condition in the nsThreadManager::RegisterCurrentThread function in Mozilla Firefox before 38.0 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) by leveraging improper Media Decoder Thread creation at the time of a shutdown.

CVSS2: 6.8
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2714

Mozilla Firefox before 38.0 on Android does not properly restrict writ ...

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2714

Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

CVSS2: 2.1
0%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2713

Use-after-free vulnerability in the SetBreaks function in Mozilla Fire ...

CVSS2: 6.8
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2713

Use-after-free vulnerability in the SetBreaks function in Mozilla Firefox before 38.0, Firefox ESR 31.x before 31.7, and Thunderbird before 31.7 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a document containing crafted text in conjunction with a Cascading Style Sheets (CSS) token sequence containing properties related to vertical text.

CVSS2: 6.8
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2712

The asm.js implementation in Mozilla Firefox before 38.0 does not prop ...

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-2712

The asm.js implementation in Mozilla Firefox before 38.0 does not properly determine heap lengths during identification of cases in which bounds checking may be safely skipped, which allows remote attackers to trigger out-of-bounds write operations and possibly execute arbitrary code, or trigger out-of-bounds read operations and possibly obtain sensitive information from process memory, via crafted JavaScript.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-2711

Mozilla Firefox before 38.0 does not recognize a referrer policy deliv ...

CVSS2: 4.3
2%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться