Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2014-1531

больше 12 лет назад

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeig ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2014-1531

больше 12 лет назад

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that is not properly handled during an image-resize operation.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2014-1530

больше 12 лет назад

The docshell implementation in Mozilla Firefox before 29.0, Firefox ES ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2014-1530

больше 12 лет назад

The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2014-1529

больше 12 лет назад

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 2 ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2014-1529

больше 12 лет назад

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2014-1528

больше 12 лет назад

The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2014-1528

больше 12 лет назад

The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2014-1527

больше 12 лет назад

Mozilla Firefox before 29.0 on Android allows remote attackers to spoo ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-1527

больше 12 лет назад

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-1531

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeig ...

CVSS3: 8.8
6%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1531

Use-after-free vulnerability in the nsGenericHTMLElement::GetWidthHeightForImage function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving an imgLoader object that is not properly handled during an image-resize operation.

CVSS3: 8.8
6%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1530

The docshell implementation in Mozilla Firefox before 29.0, Firefox ES ...

CVSS3: 6.1
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1530

The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.

CVSS3: 6.1
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1529

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 2 ...

CVSS3: 8.8
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1529

The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.

CVSS3: 8.8
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1528

The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo ...

CVSS2: 10
6%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1528

The sse2_composite_src_x888_8888 function in Pixman, as used in Cairo in Mozilla Firefox 28.0 and SeaMonkey 2.25 on Windows, allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by painting on a CANVAS element.

CVSS2: 10
6%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1527

Mozilla Firefox before 29.0 on Android allows remote attackers to spoo ...

CVSS2: 5
1%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1527

Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.

CVSS2: 5
1%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться