Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2010-1213

больше 15 лет назад

The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-1213

больше 15 лет назад

The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3. ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-1212

больше 15 лет назад

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::record_JSOP_BINDNAME function, (2) depth handling in the TraceRecorder::record_JSOP_GETELEM function, and (3) tracing of out-of-range arguments in the TraceRecorder::record_JSOP_ARGSUB function.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1212

больше 15 лет назад

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x bef ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-1211

больше 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1211

больше 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-1210

больше 15 лет назад

intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-1210

больше 15 лет назад

intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3. ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-1209

больше 15 лет назад

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1209

больше 15 лет назад

Use-after-free vulnerability in the NodeIterator implementation in Moz ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-1213

The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 does not verify that content is valid JavaScript code, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via a crafted HTML document.

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1213

The importScripts Web Worker method in Mozilla Firefox 3.5.x before 3. ...

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1212

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x before 3.6.7 and Thunderbird 3.1.x before 3.1.1 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) propagation of deep aborts in the TraceRecorder::record_JSOP_BINDNAME function, (2) depth handling in the TraceRecorder::record_JSOP_GETELEM function, and (3) tracing of out-of-range arguments in the TraceRecorder::record_JSOP_ARGSUB function.

CVSS2: 9.3
2%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1212

js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6.x bef ...

CVSS2: 9.3
2%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1211

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
4%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1211

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 9.3
4%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1210

intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1210

intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3. ...

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1209

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.

CVSS2: 9.3
2%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1209

Use-after-free vulnerability in the NodeIterator implementation in Moz ...

CVSS2: 9.3
2%
Низкий
больше 15 лет назад

Уязвимостей на страницу


Поделиться