Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2013-6167

больше 12 лет назад

Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2013-6167

больше 12 лет назад

Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-1491

больше 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozi ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1491

больше 12 лет назад

Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-1490

больше 12 лет назад

Race condition in libssl in Mozilla Network Security Services (NSS) be ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2014-1490

больше 12 лет назад

Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2014-1489

больше 12 лет назад

Mozilla Firefox before 27.0 does not properly restrict access to about ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1489

больше 12 лет назад

Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-1488

больше 12 лет назад

The Web workers implementation in Mozilla Firefox before 27.0 and SeaM ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2014-1488

больше 12 лет назад

The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-6167

Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
ubuntu логотип
CVE-2013-6167

Mozilla Firefox through 27 sends HTTP Cookie headers without first validating that they have the required character-set restrictions, which allows remote attackers to conduct the equivalent of a persistent Logout CSRF attack via a crafted parameter that forces a web application to set a malformed cookie within an HTTP response.

CVSS2: 6.8
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1491

Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozi ...

CVSS2: 4.3
5%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1491

Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanisms in ticket handling by leveraging use of a certain value.

CVSS2: 4.3
5%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1490

Race condition in libssl in Mozilla Network Security Services (NSS) be ...

CVSS2: 9.3
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1490

Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involving a resumption handshake that triggers incorrect replacement of a session ticket.

CVSS2: 9.3
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1489

Mozilla Firefox before 27.0 does not properly restrict access to about ...

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1489

Mozilla Firefox before 27.0 does not properly restrict access to about:home buttons by script on other pages, which allows user-assisted remote attackers to cause a denial of service (session restore) via a crafted web site.

CVSS2: 4.3
2%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1488

The Web workers implementation in Mozilla Firefox before 27.0 and SeaM ...

CVSS2: 10
7%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1488

The Web workers implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving termination of a worker process that has performed a cross-thread object-passing operation in conjunction with use of asm.js.

CVSS2: 10
7%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться