Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 220

debian логотип

CVE-2009-3375

около 16 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-3374

около 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3374

около 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3373

около 16 лет назад

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2009-3373

около 16 лет назад

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2009-3372

около 16 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2009-3372

около 16 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-3371

около 16 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-3371

около 16 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 all ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-3370

около 16 лет назад

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2009-3375

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x ...

CVSS2: 4.3
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
1%
Низкий
около 16 лет назад
debian логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
1%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-3373

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
13%
Средний
около 16 лет назад
debian логотип
CVE-2009-3373

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox ...

CVSS2: 10
13%
Средний
около 16 лет назад
nvd логотип
CVE-2009-3372

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.

CVSS2: 9.3
2%
Низкий
около 16 лет назад
debian логотип
CVE-2009-3372

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-3371

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

CVSS2: 10
3%
Низкий
около 16 лет назад
debian логотип
CVE-2009-3371

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 all ...

CVSS2: 10
3%
Низкий
около 16 лет назад
nvd логотип
CVE-2009-3370

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.

CVSS2: 5
1%
Низкий
около 16 лет назад

Уязвимостей на страницу


Поделиться