Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2024-9399

больше 1 года назад

A website configured to initiate a specially crafted WebTransport sess ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-9398

больше 1 года назад

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-9398

больше 1 года назад

By checking the result of calls to `window.open` with specifically set ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-9397

больше 1 года назад

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-9397

больше 1 года назад

A missing delay in directory upload UI could have made it possible for ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-9396

больше 1 года назад

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-9396

больше 1 года назад

It is currently unknown if this issue is exploitable but a condition m ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2024-9395

больше 1 года назад

A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-9395

больше 1 года назад

A specially crafted filename containing a large number of spaces could ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2024-9394

больше 1 года назад

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-9399

A website configured to initiate a specially crafted WebTransport sess ...

CVSS3: 7.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9398

By checking the result of calls to `window.open` with specifically set protocol handlers, an attacker could determine if the application which implements that protocol handler is installed. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9398

By checking the result of calls to `window.open` with specifically set ...

CVSS3: 5.3
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9397

A missing delay in directory upload UI could have made it possible for an attacker to trick a user into granting permission via clickjacking. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9397

A missing delay in directory upload UI could have made it possible for ...

CVSS3: 6.1
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9396

It is currently unknown if this issue is exploitable but a condition may arise where the structured clone of certain objects could lead to memory corruption. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 8.8
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9396

It is currently unknown if this issue is exploitable but a condition m ...

CVSS3: 8.8
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9395

A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVSS3: 5.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-9395

A specially crafted filename containing a large number of spaces could ...

CVSS3: 5.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-9394

An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This access is limited to "same site" documents by the Site Isolation feature on desktop clients, but full cross-origin access is possible on Android versions. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird < 128.3, and Thunderbird < 131.

CVSS3: 7.5
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться