Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2014-1514

больше 12 лет назад

vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by triggering incorrect use of the TypedArrayObject class.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2014-1513

больше 12 лет назад

TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2014-1513

больше 12 лет назад

TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based out-of-bounds write or read) via a crafted web site.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2014-1512

больше 12 лет назад

Use-after-free vulnerability in the TypeObject class in the JavaScript ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2014-1512

больше 12 лет назад

Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper handling of BumpChunk objects.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2014-1511

больше 12 лет назад

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird ...

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2014-1511

больше 12 лет назад

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2014-1510

больше 12 лет назад

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR ...

CVSS3: 9.8
EPSS: Высокий
nvd логотип

CVE-2014-1510

больше 12 лет назад

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2014-1509

больше 12 лет назад

Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-1514

vmtypedarrayobject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not validate the length of the destination array before a copy operation, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds write and application crash) by triggering incorrect use of the TypedArrayObject class.

CVSS3: 9.8
6%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1513

TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x ...

CVSS3: 8.8
6%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1513

TypedArrayObject.cpp in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 does not prevent a zero-length transition during use of an ArrayBuffer object, which allows remote attackers to execute arbitrary code or cause a denial of service (heap-based out-of-bounds write or read) via a crafted web site.

CVSS3: 8.8
6%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1512

Use-after-free vulnerability in the TypeObject class in the JavaScript ...

CVSS2: 10
31%
Средний
больше 12 лет назад
nvd логотип
CVE-2014-1512

Use-after-free vulnerability in the TypeObject class in the JavaScript engine in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary code by triggering extensive memory consumption while garbage collection is occurring, as demonstrated by improper handling of BumpChunk objects.

CVSS2: 10
31%
Средний
больше 12 лет назад
debian логотип
CVE-2014-1511

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird ...

CVSS3: 9.8
84%
Высокий
больше 12 лет назад
nvd логотип
CVE-2014-1511

Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypass the popup blocker via unspecified vectors.

CVSS3: 9.8
84%
Высокий
больше 12 лет назад
debian логотип
CVE-2014-1510

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR ...

CVSS3: 9.8
82%
Высокий
больше 12 лет назад
nvd логотип
CVE-2014-1510

The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to execute arbitrary JavaScript code with chrome privileges by using an IDL fragment to trigger a window.open call.

CVSS3: 9.8
82%
Высокий
больше 12 лет назад
debian логотип
CVE-2014-1509

Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo ...

CVSS3: 8.8
5%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться