Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2014-1502

больше 12 лет назад

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-1501

больше 12 лет назад

Mozilla Firefox before 28.0 on Android allows remote attackers to bypa ...

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2014-1501

больше 12 лет назад

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2014-1500

больше 12 лет назад

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-1500

больше 12 лет назад

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-1499

больше 12 лет назад

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1499

больше 12 лет назад

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-1498

больше 12 лет назад

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 a ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2014-1498

больше 12 лет назад

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2014-1497

больше 12 лет назад

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox b ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2014-1502

The (1) WebGL.compressedTexImage2D and (2) WebGL.compressedTexSubImage2D functions in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to bypass the Same Origin Policy and render content in a different domain via unspecified vectors.

CVSS2: 6.8
1%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1501

Mozilla Firefox before 28.0 on Android allows remote attackers to bypa ...

CVSS2: 5.8
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1501

Mozilla Firefox before 28.0 on Android allows remote attackers to bypass the Same Origin Policy and access arbitrary file: URLs via vectors involving the "Open Link in New Tab" menu selection.

CVSS2: 5.8
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1500

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ...

CVSS2: 5
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1500

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to cause a denial of service (resource consumption and application hang) via onbeforeunload events that trigger background JavaScript execution.

CVSS2: 5
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1499

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote att ...

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1499

Mozilla Firefox before 28.0 and SeaMonkey before 2.25 allow remote attackers to spoof the domain name in the WebRTC (1) camera or (2) microphone permission prompt by triggering navigation at a certain time during generation of this prompt.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1498

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 a ...

CVSS2: 5
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1498

The crypto.generateCRMFRequest method in Mozilla Firefox before 28.0 and SeaMonkey before 2.25 does not properly validate a certain key type, which allows remote attackers to cause a denial of service (application crash) via vectors that trigger generation of a key that supports the Elliptic Curve ec-dual-use algorithm.

CVSS2: 5
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1497

The mozilla::WaveReader::DecodeAudioData function in Mozilla Firefox b ...

CVSS3: 8.8
3%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться