Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2013-1715

около 13 лет назад

Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2013-1714

около 13 лет назад

The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1714

около 13 лет назад

The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1713

около 13 лет назад

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbi ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1713

около 13 лет назад

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons via a crafted web site.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1712

около 13 лет назад

Multiple untrusted search path vulnerabilities in updater.exe in Mozil ...

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2013-1712

около 13 лет назад

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update directory or (2) the current working directory.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2013-1711

около 13 лет назад

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaM ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1711

около 13 лет назад

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1710

около 13 лет назад

The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0 ...

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-1715

Multiple untrusted search path vulnerabilities in the (1) full installer and (2) stub installer in Mozilla Firefox before 23.0 on Windows allow local users to gain privileges via a Trojan horse DLL in the default downloads directory. NOTE: this issue exists because of an incomplete fix for CVE-2012-4206.

CVSS2: 6.9
0%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1714

The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ...

CVSS2: 4.3
2%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1714

The Web Workers implementation in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 does not properly restrict XMLHttpRequest calls, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via unspecified vectors.

CVSS2: 4.3
2%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1713

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbi ...

CVSS2: 4.3
2%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1713

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 use an incorrect URI within unspecified comparisons during enforcement of the Same Origin Policy, which allows remote attackers to conduct cross-site scripting (XSS) attacks or install arbitrary add-ons via a crafted web site.

CVSS2: 4.3
2%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1712

Multiple untrusted search path vulnerabilities in updater.exe in Mozil ...

CVSS2: 6.9
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1712

Multiple untrusted search path vulnerabilities in updater.exe in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 on Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012 allow local users to gain privileges via a Trojan horse DLL in (1) the update directory or (2) the current working directory.

CVSS2: 6.9
0%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1711

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaM ...

CVSS2: 4.3
2%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1711

The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.

CVSS2: 4.3
2%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1710

The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0 ...

CVSS2: 10
40%
Средний
около 13 лет назад

Уязвимостей на страницу


Поделиться