Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2014-1509

больше 12 лет назад

Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2014-1508

больше 12 лет назад

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 2 ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2014-1508

больше 12 лет назад

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2014-1506

больше 12 лет назад

Directory traversal vulnerability in Android Crash Reporter in Mozilla ...

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2014-1506

больше 12 лет назад

Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2014-1505

больше 12 лет назад

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-1505

больше 12 лет назад

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2014-1504

больше 12 лет назад

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonk ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2014-1504

больше 12 лет назад

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2014-1502

больше 12 лет назад

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage ...

CVSS2: 6.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-1509

Buffer overflow in the _cairo_truetype_index_to_ucs4 function in cairo, as used in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25, allows remote attackers to execute arbitrary code via a crafted extension that renders fonts in a PDF document.

CVSS3: 8.8
5%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1508

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 2 ...

CVSS3: 9.1
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1508

The libxul.so!gfxContext::Polygon function in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive information from process memory, cause a denial of service (out-of-bounds read and application crash), or possibly bypass the Same Origin Policy via vectors involving MathML polygon rendering.

CVSS3: 9.1
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1506

Directory traversal vulnerability in Android Crash Reporter in Mozilla ...

CVSS2: 6.4
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1506

Directory traversal vulnerability in Android Crash Reporter in Mozilla Firefox before 28.0 on Android allows attackers to trigger the transmission of local files to arbitrary servers, or cause a denial of service (application crash), via a crafted application that specifies Android Crash Reporter arguments.

CVSS2: 6.4
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1505

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ...

CVSS3: 7.5
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1505

The SVG filter implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allows remote attackers to obtain sensitive displacement-correlation information, and possibly bypass the Same Origin Policy and read text from a different domain, via a timing attack involving feDisplacementMap elements, a related issue to CVE-2013-1693.

CVSS3: 7.5
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1504

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonk ...

CVSS2: 2.6
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1504

The session-restore feature in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not consider the Content Security Policy of a data: URL, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted document that is accessed after a browser restart.

CVSS2: 2.6
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1502

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage ...

CVSS2: 6.8
1%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться