Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2013-1726

почти 13 лет назад

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

CVSS2: 6.2
EPSS: Низкий
debian логотип

CVE-2013-1725

почти 13 лет назад

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbi ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2013-1725

почти 13 лет назад

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2013-1724

почти 13 лет назад

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsD ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2013-1724

почти 13 лет назад

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2013-1723

почти 13 лет назад

The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird befor ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1723

почти 13 лет назад

The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 processes key messages after destruction by a dispatched event listener, which allows remote attackers to cause a denial of service (application crash) by leveraging incorrect event usage after widget-memory reallocation.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1722

почти 13 лет назад

Use-after-free vulnerability in the nsAnimationManager::BuildAnimation ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2013-1722

почти 13 лет назад

Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving stylesheet cloning.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2013-1721

почти 13 лет назад

Integer overflow in the drawLineLoop function in the libGLESv2 library ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-1726

Mozilla Updater in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 does not ensure exclusive access to a MAR file, which allows local users to gain privileges by creating a Trojan horse file after MAR signature verification but before MAR use.

CVSS2: 6.2
0%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-1725

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbi ...

CVSS2: 6.8
4%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-1725

Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 do not ensure that initialization occurs for JavaScript objects with compartments, which allows remote attackers to execute arbitrary code by leveraging incorrect scope handling.

CVSS2: 6.8
4%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-1724

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsD ...

CVSS2: 9.3
6%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-1724

Use-after-free vulnerability in the mozilla::dom::HTMLFormElement::IsDefaultSubmitElement function in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving a destroyed SELECT element.

CVSS2: 9.3
6%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-1723

The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird befor ...

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-1723

The NativeKey widget in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 processes key messages after destruction by a dispatched event listener, which allows remote attackers to cause a denial of service (application crash) by leveraging incorrect event usage after widget-memory reallocation.

CVSS2: 4.3
2%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-1722

Use-after-free vulnerability in the nsAnimationManager::BuildAnimation ...

CVSS2: 9.3
6%
Низкий
почти 13 лет назад
nvd логотип
CVE-2013-1722

Use-after-free vulnerability in the nsAnimationManager::BuildAnimations function in the Animation Manager in Mozilla Firefox before 24.0, Firefox ESR 17.x before 17.0.9, Thunderbird before 24.0, Thunderbird ESR 17.x before 17.0.9, and SeaMonkey before 2.21 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving stylesheet cloning.

CVSS2: 9.3
6%
Низкий
почти 13 лет назад
debian логотип
CVE-2013-1721

Integer overflow in the drawLineLoop function in the libGLESv2 library ...

CVSS2: 9.3
4%
Низкий
почти 13 лет назад

Уязвимостей на страницу


Поделиться