Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2013-5596

почти 13 лет назад

The cycle collection (CC) implementation in Mozilla Firefox before 25. ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-5596

почти 13 лет назад

The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly determine the thread for release of an image object, which allows remote attackers to execute arbitrary code or cause a denial of service (race condition and application crash) via a large HTML document containing IMG elements, as demonstrated by the Never-Ending Reddit on reddit.com.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-5595

почти 13 лет назад

The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5595

почти 13 лет назад

The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly allocate memory for unspecified functions, which allows remote attackers to conduct buffer overflow attacks via a crafted web page.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-5593

почти 13 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Fire ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-5593

почти 13 лет назад

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-5592

почти 13 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2013-5592

почти 13 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2013-5591

почти 13 лет назад

Unspecified vulnerability in the browser engine in Mozilla Firefox bef ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2013-5591

почти 13 лет назад

Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-5596

The cycle collection (CC) implementation in Mozilla Firefox before 25. ...

CVSS2: 6.8
3%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5596

The cycle collection (CC) implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly determine the thread for release of an image object, which allows remote attackers to execute arbitrary code or cause a denial of service (race condition and application crash) via a large HTML document containing IMG elements, as demonstrated by the Never-Ending Reddit on reddit.com.

CVSS2: 6.8
3%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-5595

The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x ...

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5595

The JavaScript engine in Mozilla Firefox before 25.0, Firefox ESR 17.x before 17.0.10 and 24.x before 24.1, Thunderbird before 24.1, Thunderbird ESR 17.x before 17.0.10, and SeaMonkey before 2.22 does not properly allocate memory for unspecified functions, which allows remote attackers to conduct buffer overflow attacks via a crafted web page.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-5593

The SELECT element implementation in Mozilla Firefox before 25.0, Fire ...

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5593

The SELECT element implementation in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 does not properly restrict the nature or placement of HTML within a dropdown menu, which allows remote attackers to spoof the address bar or conduct clickjacking attacks via vectors that trigger navigation off of a page containing this element.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-5592

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
5%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5592

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 25.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
5%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-5591

Unspecified vulnerability in the browser engine in Mozilla Firefox bef ...

CVSS2: 10
4%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-5591

Unspecified vulnerability in the browser engine in Mozilla Firefox before 25.0, Firefox ESR 24.x before 24.1, Thunderbird before 24.1, and SeaMonkey before 2.22 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
4%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться