Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2013-1710

около 13 лет назад

The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message Format (CRMF) request generation.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2013-1709

около 13 лет назад

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbi ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1709

около 13 лет назад

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in a previously visited document.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1708

около 13 лет назад

Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote att ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1708

около 13 лет назад

Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1707

около 13 лет назад

Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox befo ...

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2013-1707

около 13 лет назад

Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2013-1706

около 13 лет назад

Stack-based buffer overflow in maintenanceservice.exe in the Mozilla M ...

CVSS2: 7.2
EPSS: Низкий
nvd логотип

CVE-2013-1706

около 13 лет назад

Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2013-1705

около 13 лет назад

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type fun ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-1710

The crypto.generateCRMFRequest function in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 allows remote attackers to execute arbitrary JavaScript code or conduct cross-site scripting (XSS) attacks via vectors related to Certificate Request Message Format (CRMF) request generation.

CVSS2: 10
40%
Средний
около 13 лет назад
debian логотип
CVE-2013-1709

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbi ...

CVSS2: 4.3
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1709

Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, Thunderbird ESR 17.x before 17.0.8, and SeaMonkey before 2.20 do not properly handle the interaction between FRAME elements and history, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors involving spoofing a relative location in a previously visited document.

CVSS2: 4.3
1%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1708

Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote att ...

CVSS2: 4.3
3%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1708

Mozilla Firefox before 23.0 and SeaMonkey before 2.20 allow remote attackers to cause a denial of service (application crash) via a crafted WAV file that is not properly handled by the nsCString::CharAt function.

CVSS2: 4.3
3%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1707

Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox befo ...

CVSS2: 7.2
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1707

Stack-based buffer overflow in Mozilla Updater in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line to the Mozilla Maintenance Service.

CVSS2: 7.2
0%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1706

Stack-based buffer overflow in maintenanceservice.exe in the Mozilla M ...

CVSS2: 7.2
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1706

Stack-based buffer overflow in maintenanceservice.exe in the Mozilla Maintenance Service in Mozilla Firefox before 23.0, Firefox ESR 17.x before 17.0.8, Thunderbird before 17.0.8, and Thunderbird ESR 17.x before 17.0.8 allows local users to gain privileges via a long pathname on the command line.

CVSS2: 7.2
0%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1705

Heap-based buffer underflow in the cryptojs_interpret_key_gen_type fun ...

CVSS2: 10
4%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться