Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

fstec логотип

BDU:2015-10028

больше 11 лет назад

Уязвимость браузера Firefox, позволяющая нарушителю вызвать отказ в обслуживании

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0799

больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0799

больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-0798

больше 11 лет назад

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, a ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2015-0798

больше 11 лет назад

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2015-0799

больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2015-0799

больше 11 лет назад

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

CVSS2: 5.8
EPSS: Низкий
fstec логотип

BDU:2015-09904

больше 11 лет назад

Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти проверку сертификата

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-0816

больше 11 лет назад

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunder ...

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2015-0816

больше 11 лет назад

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

CVSS2: 5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2015-10028

Уязвимость браузера Firefox, позволяющая нарушителю вызвать отказ в обслуживании

CVSS2: 6.8
3%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0799

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 ...

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0799

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0798

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, a ...

CVSS2: 5
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0798

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.

CVSS2: 5
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0799

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-0799

The HTTP Alternative Services feature in Mozilla Firefox before 37.0.1 allows man-in-the-middle attackers to bypass an intended X.509 certificate-verification step for an SSL server by specifying that server in the uri-host field of an Alt-Svc HTTP/2 response header.

CVSS2: 5.8
1%
Низкий
больше 11 лет назад
fstec логотип
BDU:2015-09904

Уязвимость браузера Firefox, позволяющая удалённому злоумышленнику обойти проверку сертификата

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0816

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunder ...

CVSS2: 5
67%
Средний
больше 11 лет назад
nvd логотип
CVE-2015-0816

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 do not properly restrict resource: URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy, as demonstrated by the resource: URL associated with PDF.js.

CVSS2: 5
67%
Средний
больше 11 лет назад

Уязвимостей на страницу


Поделиться