Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2010-1200

больше 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1200

больше 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-1199

больше 15 лет назад

Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2010-1199

больше 15 лет назад

Integer overflow in the XSLT node sorting implementation in Mozilla Fi ...

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2010-1198

больше 15 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1198

больше 15 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 an ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-1197

больше 15 лет назад

Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-1197

больше 15 лет назад

Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMon ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-1196

больше 15 лет назад

Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1196

больше 15 лет назад

Integer overflow in the nsGenericDOMDataNode::SetTextInternal function ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-1200

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 9.3
5%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1200

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 9.3
5%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1199

Integer overflow in the XSLT node sorting implementation in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a large text value for a node.

CVSS2: 9.3
47%
Средний
больше 15 лет назад
debian логотип
CVE-2010-1199

Integer overflow in the XSLT node sorting implementation in Mozilla Fi ...

CVSS2: 9.3
47%
Средний
больше 15 лет назад
nvd логотип
CVE-2010-1198

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, allows remote attackers to execute arbitrary code via vectors involving multiple plugin instances.

CVSS2: 9.3
6%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1198

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.10 an ...

CVSS2: 9.3
6%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1197

Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMonkey before 2.0.5, does not properly handle situations in which both "Content-Disposition: attachment" and "Content-Type: multipart" are present in HTTP headers, which allows remote attackers to conduct cross-site scripting (XSS) attacks via an uploaded HTML document.

CVSS2: 4.3
1%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1197

Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, and SeaMon ...

CVSS2: 4.3
1%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-1196

Integer overflow in the nsGenericDOMDataNode::SetTextInternal function in Mozilla Firefox 3.5.x before 3.5.10 and 3.6.x before 3.6.4, Thunderbird before 3.0.5, and SeaMonkey before 2.0.5 allows remote attackers to execute arbitrary code via a DOM node with a long text value that triggers a heap-based buffer overflow.

CVSS2: 9.3
5%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-1196

Integer overflow in the nsGenericDOMDataNode::SetTextInternal function ...

CVSS2: 9.3
5%
Низкий
больше 15 лет назад

Уязвимостей на страницу


Поделиться