Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2015-0810

больше 11 лет назад

Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0810

больше 11 лет назад

Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-0808

больше 11 лет назад

The webrtc::VPMContentAnalysis::Release function in the WebRTC impleme ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2015-0808

больше 11 лет назад

The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2015-0807

больше 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0 ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-0807

больше 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0806

больше 11 лет назад

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-0806

больше 11 лет назад

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-0805

больше 11 лет назад

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-0805

больше 11 лет назад

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors that trigger rendering of 2D graphics content.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-0810

Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is ...

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0810

Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0808

The webrtc::VPMContentAnalysis::Release function in the WebRTC impleme ...

CVSS2: 5
3%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0808

The webrtc::VPMContentAnalysis::Release function in the WebRTC implementation in Mozilla Firefox before 37.0 uses incompatible approaches to the deallocation of memory for simple-type arrays, which might allow remote attackers to cause a denial of service (memory corruption) via unspecified vectors.

CVSS2: 5
3%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0807

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0 ...

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0807

The navigator.sendBeacon implementation in Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 processes HTTP 30x status codes for redirects after a preflight request has occurred, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site, a similar issue to CVE-2014-8638.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0806

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ...

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0806

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0805

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firef ...

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0805

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 makes an incorrect memset call during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors that trigger rendering of 2D graphics content.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться