Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

redhat логотип

CVE-2015-0824

больше 11 лет назад

The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2015-0823

больше 11 лет назад

Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-8640

больше 11 лет назад

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-8637

больше 11 лет назад

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.

CVSS2: 5.1
EPSS: Низкий
redhat логотип

CVE-2014-8642

больше 11 лет назад

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2014-8635

больше 11 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-8643

больше 11 лет назад

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypa ...

CVSS2: 7.1
EPSS: Низкий
nvd логотип

CVE-2014-8643

больше 11 лет назад

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

CVSS2: 7.1
EPSS: Низкий
debian логотип

CVE-2014-8642

больше 11 лет назад

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-8642

больше 11 лет назад

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2015-0824

The mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 36.0 allows remote attackers to cause a denial of service (out-of-bounds write of zero values, and application crash) via vectors that trigger use of DrawTarget and the Cairo library for image drawing.

CVSS2: 5.1
4%
Низкий
больше 11 лет назад
redhat логотип
CVE-2015-0823

Multiple use-after-free vulnerabilities in OpenType Sanitiser, as used in Mozilla Firefox before 36.0, might allow remote attackers to trigger problematic Developer Console information or possibly have unspecified other impact by leveraging incorrect macro expansion, related to the ots::ots_gasp_parse function.

CVSS2: 4.3
4%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8640

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8637

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.

CVSS2: 5.1
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8642

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
redhat логотип
CVE-2014-8635

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 6.8
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-8643

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypa ...

CVSS2: 7.1
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-8643

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

CVSS2: 7.1
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-8642

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider ...

CVSS2: 4.3
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-8642

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not consider the id-pkix-ocsp-nocheck extension in deciding whether to trust an OCSP responder, which makes it easier for remote attackers to obtain sensitive information by sniffing the network during a session in which there was an incorrect decision to accept a compromised and revoked certificate.

CVSS2: 4.3
2%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться