Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2014-1526

больше 12 лет назад

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaM ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-1526

больше 12 лет назад

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-1525

больше 12 лет назад

The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2014-1525

больше 12 лет назад

The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2014-1524

больше 12 лет назад

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2014-1524

больше 12 лет назад

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted JavaScript code that accesses a non-XBL object as if it were an XBL object.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2014-1523

больше 12 лет назад

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2014-1523

больше 12 лет назад

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2014-1522

больше 12 лет назад

The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2014-1522

больше 12 лет назад

The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via crafted content.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-1526

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaM ...

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1526

The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1525

The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before ...

CVSS2: 9.3
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1525

The mozilla::dom::TextTrack::AddCue function in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 does not properly perform garbage collection for Text Track Manager variables, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free and heap memory corruption) via a crafted VIDEO element in an HTML document.

CVSS2: 9.3
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1524

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox ...

CVSS3: 9.8
8%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1524

The nsXBLProtoImpl::InstallImplementation function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 does not properly check whether objects are XBL objects, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted JavaScript code that accesses a non-XBL object as if it were an XBL object.

CVSS3: 9.8
8%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1523

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox ...

CVSS3: 6.5
3%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1523

Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted JPEG image.

CVSS3: 6.5
3%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1522

The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the ...

CVSS2: 9.3
5%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1522

The mozilla::dom::OscillatorNodeEngine::ComputeCustom function in the Web Audio subsystem in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read, memory corruption, and application crash) via crafted content.

CVSS2: 9.3
5%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться