Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2014-1482

больше 12 лет назад

RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x befor ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2014-1482

больше 12 лет назад

RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2014-1481

больше 12 лет назад

Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-1481

больше 12 лет назад

Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2014-1480

больше 12 лет назад

The file-download implementation in Mozilla Firefox before 27.0 and Se ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-1480

больше 12 лет назад

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2014-1479

больше 12 лет назад

The System Only Wrapper (SOW) implementation in Mozilla Firefox before ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2014-1479

больше 12 лет назад

The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2014-1478

больше 12 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2014-1478

больше 12 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the MPostWriteBarrier class in js/src/jit/MIR.h and stack alignment in js/src/jit/AsmJS.cpp in OdinMonkey, and unknown other vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2014-1482

RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x befor ...

CVSS3: 8.8
6%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1482

RasterImage.cpp in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent access to discarded data, which allows remote attackers to execute arbitrary code or cause a denial of service (incorrect write operations) via crafted image data, as demonstrated by Goo Create.

CVSS3: 8.8
6%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1481

Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird ...

CVSS3: 7.5
4%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1481

Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to bypass intended restrictions on window objects by leveraging inconsistency in native getter methods across different JavaScript engines.

CVSS3: 7.5
4%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1480

The file-download implementation in Mozilla Firefox before 27.0 and Se ...

CVSS2: 4.3
3%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1480

The file-download implementation in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 does not properly restrict the timing of button selections, which allows remote attackers to conduct clickjacking attacks, and trigger unintended launching of a downloaded file, via a crafted web site.

CVSS2: 4.3
3%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1479

The System Only Wrapper (SOW) implementation in Mozilla Firefox before ...

CVSS3: 7.5
5%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1479

The System Only Wrapper (SOW) implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 does not prevent certain cloning operations, which allows remote attackers to bypass intended restrictions on XUL content via vectors involving XBL content scopes.

CVSS3: 7.5
5%
Низкий
больше 12 лет назад
debian логотип
CVE-2014-1478

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
7%
Низкий
больше 12 лет назад
nvd логотип
CVE-2014-1478

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0 and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the MPostWriteBarrier class in js/src/jit/MIR.h and stack alignment in js/src/jit/AsmJS.cpp in OdinMonkey, and unknown other vectors.

CVSS2: 10
7%
Низкий
больше 12 лет назад

Уязвимостей на страницу


Поделиться