Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2010-0170

почти 16 лет назад

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected w ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-0169

почти 16 лет назад

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2010-0169

почти 16 лет назад

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoade ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-0168

почти 16 лет назад

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.

CVSS2: 7.6
EPSS: Низкий
debian логотип

CVE-2010-0168

почти 16 лет назад

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocum ...

CVSS2: 7.6
EPSS: Низкий
nvd логотип

CVE-2010-0167

почти 16 лет назад

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2010-0167

почти 16 лет назад

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x befor ...

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2010-0166

почти 16 лет назад

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

CVSS2: 5.1
EPSS: Средний
debian логотип

CVE-2010-0166

почти 16 лет назад

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.c ...

CVSS2: 5.1
EPSS: Средний
nvd логотип

CVE-2010-0165

почти 16 лет назад

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2010-0170

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected w ...

CVSS2: 4.3
0%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-0169

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.

CVSS2: 5
0%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-0169

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoade ...

CVSS2: 5
0%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-0168

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.

CVSS2: 7.6
10%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-0168

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocum ...

CVSS2: 7.6
10%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-0167

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.

CVSS2: 9.3
23%
Средний
почти 16 лет назад
debian логотип
CVE-2010-0167

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x befor ...

CVSS2: 9.3
23%
Средний
почти 16 лет назад
nvd логотип
CVE-2010-0166

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

CVSS2: 5.1
18%
Средний
почти 16 лет назад
debian логотип
CVE-2010-0166

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.c ...

CVSS2: 5.1
18%
Средний
почти 16 лет назад
nvd логотип
CVE-2010-0165

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.

CVSS2: 9.3
4%
Низкий
почти 16 лет назад

Уязвимостей на страницу


Поделиться