Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 156

debian логотип

CVE-2024-6613

больше 1 года назад

The frame iterator could get stuck in a loop when encountering certain ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-6612

больше 1 года назад

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-6612

больше 1 года назад

CSP violations generated links in the console tab of the developer too ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-6611

больше 1 года назад

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-6611

больше 1 года назад

A nested iframe, triggering a cross-site navigation, could send SameSi ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-6610

больше 1 года назад

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-6610

больше 1 года назад

Form validation popups could capture escape key presses. Therefore, sp ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-6609

больше 1 года назад

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-6609

больше 1 года назад

When almost out-of-memory an elliptic curve key which was never alloca ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2024-6608

больше 1 года назад

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-6613

The frame iterator could get stuck in a loop when encountering certain ...

CVSS3: 5.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6612

CSP violations generated links in the console tab of the developer tools, pointing to the violating resource. This caused a DNS prefetch which leaked that a CSP violation happened. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6612

CSP violations generated links in the console tab of the developer too ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6611

A nested iframe, triggering a cross-site navigation, could send SameSite=Strict or Lax cookies. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6611

A nested iframe, triggering a cross-site navigation, could send SameSi ...

CVSS3: 9.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6610

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6610

Form validation popups could capture escape key presses. Therefore, sp ...

CVSS3: 4.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6609

When almost out-of-memory an elliptic curve key which was never allocated could have been freed again. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-6609

When almost out-of-memory an elliptic curve key which was never alloca ...

CVSS3: 8.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-6608

It was possible to move the cursor using pointerlock from an iframe. This allowed moving the cursor outside of the viewport and the Firefox window. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 4.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться