Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2010-1206

больше 15 лет назад

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-1206

больше 15 лет назад

The startDocumentLoad function in browser/base/content/browser.js in M ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-1206

больше 15 лет назад

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2010-1205

больше 15 лет назад

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2010-1203

больше 15 лет назад

The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1203

больше 15 лет назад

The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remo ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-1202

больше 15 лет назад

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1202

больше 15 лет назад

Multiple unspecified vulnerabilities in the JavaScript engine in Mozil ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-1201

больше 15 лет назад

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1201

больше 15 лет назад

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5 ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-1206

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1206

The startDocumentLoad function in browser/base/content/browser.js in M ...

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
ubuntu логотип
CVE-2010-1206

The startDocumentLoad function in browser/base/content/browser.js in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, does not properly implement the Same Origin Policy in certain circumstances related to the about:blank document and a document that is currently loading, which allows (1) remote web servers to conduct spoofing attacks via vectors involving a 204 (aka No Content) status code, and allows (2) remote attackers to conduct spoofing attacks via vectors involving a window.stop call.

CVSS2: 4.3
0%
Низкий
больше 15 лет назад
redhat логотип
CVE-2010-1205

Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.

CVSS2: 6.8
15%
Средний
больше 15 лет назад
nvd логотип
CVE-2010-1203

The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors that trigger an assertion failure in jstracer.cpp.

CVSS2: 9.3
6%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1203

The JavaScript engine in Mozilla Firefox 3.6.x before 3.6.4 allow remo ...

CVSS2: 9.3
6%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1202

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
7%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1202

Multiple unspecified vulnerabilities in the JavaScript engine in Mozil ...

CVSS2: 9.3
7%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1201

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.10, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
5%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1201

Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5 ...

CVSS2: 9.3
5%
Низкий
больше 15 лет назад

Уязвимостей на страницу


Поделиться