Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2014-8641

больше 11 лет назад

Use-after-free vulnerability in the WebRTC implementation in Mozilla F ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-8641

больше 11 лет назад

Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 allows remote attackers to execute arbitrary code via crafted track data.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-8640

больше 11 лет назад

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-8640

больше 11 лет назад

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-8639

больше 11 лет назад

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-8639

больше 11 лет назад

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-8638

больше 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0 ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-8638

больше 11 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-8637

больше 11 лет назад

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-8637

больше 11 лет назад

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-8641

Use-after-free vulnerability in the WebRTC implementation in Mozilla F ...

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-8641

Use-after-free vulnerability in the WebRTC implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, and SeaMonkey before 2.32 allows remote attackers to execute arbitrary code via crafted track data.

CVSS2: 7.5
4%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-8640

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in ...

CVSS2: 5
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-8640

The mozilla::dom::AudioParamTimeline::AudioNodeInputValue function in the Web Audio API implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly restrict timeline operations, which allows remote attackers to cause a denial of service (uninitialized-memory read and application crash) via crafted API calls.

CVSS2: 5
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird ...

CVSS2: 6.8
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 6.8
2%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0 ...

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 6.8
1%
Низкий
больше 11 лет назад
debian логотип
CVE-2014-8637

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly ...

CVSS2: 5
2%
Низкий
больше 11 лет назад
nvd логотип
CVE-2014-8637

Mozilla Firefox before 35.0 and SeaMonkey before 2.32 do not properly initialize memory for BMP images, which allows remote attackers to obtain sensitive information from process memory via a crafted web page that triggers the rendering of malformed BMP data within a CANVAS element.

CVSS2: 5
2%
Низкий
больше 11 лет назад

Уязвимостей на страницу


Поделиться