Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2010-2753

больше 15 лет назад

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2010-2753

больше 15 лет назад

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x befo ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2010-2752

больше 15 лет назад

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-2752

больше 15 лет назад

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5 ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2751

больше 15 лет назад

The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2010-2751

больше 15 лет назад

The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocS ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2010-1215

больше 15 лет назад

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-1215

больше 15 лет назад

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-1214

больше 15 лет назад

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1214

больше 15 лет назад

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x befo ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-2753

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.

CVSS3: 8.8
4%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-2753

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x befo ...

CVSS3: 8.8
4%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-2752

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.

CVSS2: 9.3
8%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-2752

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5 ...

CVSS2: 9.3
8%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-2751

The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocShell.cpp in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to spoof the SSL security status of a document via vectors involving multiple requests, a redirect, and the history.back and history.forward JavaScript functions.

CVSS2: 2.6
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-2751

The nsDocShell::OnRedirectStateChange function in docshell/base/nsDocS ...

CVSS2: 2.6
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1215

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 do not properly implement access to a content object through a SafeJSObjectWrapper (aka SJOW) wrapper, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging "access to an object from the chrome scope."

CVSS2: 6.8
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1215

Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 ...

CVSS2: 6.8
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1214

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.

CVSS2: 9.3
4%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1214

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x befo ...

CVSS2: 9.3
4%
Низкий
больше 15 лет назад

Уязвимостей на страницу


Поделиться