Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2010-3771

около 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-3770

около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to angle brackets during rendering.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-3770

около 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the rendering e ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-3769

около 15 лет назад

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-3769

около 15 лет назад

The line-breaking implementation in Mozilla Firefox before 3.5.16 and ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-3768

около 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-3768

около 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird bef ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-3767

около 15 лет назад

Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-3767

около 15 лет назад

Integer overflow in the NewIdArray function in Mozilla Firefox before ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-3766

около 15 лет назад

Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via vectors involving a change to an nsDOMAttribute node.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2010-3771

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 6.8
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-3770

Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to angle brackets during rendering.

CVSS2: 4.3
9%
Низкий
около 15 лет назад
debian логотип
CVE-2010-3770

Multiple cross-site scripting (XSS) vulnerabilities in the rendering e ...

CVSS2: 4.3
9%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-3769

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

CVSS2: 9.3
7%
Низкий
около 15 лет назад
debian логотип
CVE-2010-3769

The line-breaking implementation in Mozilla Firefox before 3.5.16 and ...

CVSS2: 9.3
7%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-3768

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 do not properly validate downloadable fonts before use within an operating system's font implementation, which allows remote attackers to execute arbitrary code via vectors related to @font-face Cascading Style Sheets (CSS) rules.

CVSS2: 9.3
7%
Низкий
около 15 лет назад
debian логотип
CVE-2010-3768

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird bef ...

CVSS2: 9.3
7%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-3767

Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.

CVSS2: 9.3
5%
Низкий
около 15 лет назад
debian логотип
CVE-2010-3767

Integer overflow in the NewIdArray function in Mozilla Firefox before ...

CVSS2: 9.3
5%
Низкий
около 15 лет назад
nvd логотип
CVE-2010-3766

Use-after-free vulnerability in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via vectors involving a change to an nsDOMAttribute node.

CVSS2: 9.3
7%
Низкий
около 15 лет назад

Уязвимостей на страницу


Поделиться