Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2015-0804

больше 11 лет назад

The HTMLSourceElement::BindToTree function in Mozilla Firefox before 3 ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-0804

больше 11 лет назад

The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-0803

больше 11 лет назад

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-0803

больше 11 лет назад

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-0802

больше 11 лет назад

Mozilla Firefox before 37.0 relies on docshell type information instea ...

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2015-0802

больше 11 лет назад

Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2015-0801

больше 11 лет назад

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunder ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2015-0801

больше 11 лет назад

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-0800

больше 11 лет назад

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fe ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2015-0800

больше 11 лет назад

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2012-2808.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-0804

The HTMLSourceElement::BindToTree function in Mozilla Firefox before 3 ...

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0804

The HTMLSourceElement::BindToTree function in Mozilla Firefox before 37.0 does not properly constrain a data type after omitting namespace validation during certain tree-binding operations, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document containing a SOURCE element.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0803

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before ...

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0803

The HTMLSourceElement::AfterSetAttr function in Mozilla Firefox before 37.0 does not properly constrain the original data type of a casted value during the setting of a SOURCE element's attributes, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted HTML document.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0802

Mozilla Firefox before 37.0 relies on docshell type information instea ...

CVSS2: 5
67%
Средний
больше 11 лет назад
nvd логотип
CVE-2015-0802

Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl access control, which might allow remote attackers to execute arbitrary JavaScript code with chrome privileges via certain content navigation that leverages the reachability of a privileged window with an unintended persistence of access to restricted internal methods.

CVSS2: 5
67%
Средний
больше 11 лет назад
debian логотип
CVE-2015-0801

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunder ...

CVSS2: 7.5
3%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0801

Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

CVSS2: 7.5
3%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0800

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fe ...

CVSS2: 5
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0800

The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2012-2808.

CVSS2: 5
2%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться