Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2015-0822

больше 11 лет назад

The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0822

больше 11 лет назад

The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2015-0821

больше 11 лет назад

Mozilla Firefox before 36.0 allows user-assisted remote attackers to r ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-0821

больше 11 лет назад

Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2015-0820

больше 11 лет назад

Mozilla Firefox before 36.0 does not properly restrict transitions of ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2015-0820

больше 11 лет назад

Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2015-0819

больше 11 лет назад

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does n ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2015-0819

больше 11 лет назад

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0834

больше 11 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2015-0835

больше 11 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2015-0822

The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefo ...

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0822

The Form Autocompletion feature in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to read arbitrary files via crafted JavaScript code.

CVSS2: 4.3
3%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0821

Mozilla Firefox before 36.0 allows user-assisted remote attackers to r ...

CVSS2: 6.8
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0821

Mozilla Firefox before 36.0 allows user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions.

CVSS2: 6.8
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0820

Mozilla Firefox before 36.0 does not properly restrict transitions of ...

CVSS2: 2.6
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0820

Mozilla Firefox before 36.0 does not properly restrict transitions of JavaScript objects from a non-extensible state to an extensible state, which allows remote attackers to bypass a Caja Compiler sandbox protection mechanism or a Secure EcmaScript sandbox protection mechanism via a crafted web site.

CVSS2: 2.6
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2015-0819

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does n ...

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2015-0819

The UITour::onPageEvent function in Mozilla Firefox before 36.0 does not ensure that an API call originates from a foreground tab, which allows remote attackers to conduct spoofing and clickjacking attacks by leveraging access to a UI Tour web site.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0834

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

CVSS2: 4.3
1%
Низкий
больше 11 лет назад
ubuntu логотип
CVE-2015-0835

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 36.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться