Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2013-1700

около 13 лет назад

The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.

CVSS2: 7.2
EPSS: Низкий
debian логотип

CVE-2013-1699

около 13 лет назад

The Internationalized Domain Name (IDN) display algorithm in Mozilla F ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-1699

около 13 лет назад

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level domains, which allows remote attackers to spoof the address bar via unspecified homograph characters.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-1698

около 13 лет назад

The getUserMedia permission implementation in Mozilla Firefox before 2 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1698

около 13 лет назад

The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1697

около 13 лет назад

The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2013-1697

около 13 лет назад

The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2013-1696

около 13 лет назад

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Opti ...

CVSS2: 4
EPSS: Низкий
nvd логотип

CVE-2013-1696

около 13 лет назад

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

CVSS2: 4
EPSS: Низкий
debian логотип

CVE-2013-1695

около 13 лет назад

Mozilla Firefox before 22.0 does not properly implement certain DocShe ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-1700

The Mozilla Maintenance Service in Mozilla Firefox before 22.0 on Windows does not properly handle inability to launch the Mozilla Updater executable file, which allows local users to gain privileges via vectors involving placement of a Trojan horse executable file at an arbitrary location.

CVSS2: 7.2
0%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1699

The Internationalized Domain Name (IDN) display algorithm in Mozilla F ...

CVSS2: 5
2%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1699

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level domains, which allows remote attackers to spoof the address bar via unspecified homograph characters.

CVSS2: 5
2%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1698

The getUserMedia permission implementation in Mozilla Firefox before 2 ...

CVSS2: 4.3
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1698

The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.

CVSS2: 4.3
1%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1697

The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ...

CVSS2: 9.3
3%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1697

The XrayWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly restrict use of DefaultValue for method calls, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that triggers use of a user-defined (1) toString or (2) valueOf method.

CVSS2: 9.3
3%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1696

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Opti ...

CVSS2: 4
2%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1696

Mozilla Firefox before 22.0 does not properly enforce the X-Frame-Options protection mechanism, which allows remote attackers to conduct clickjacking attacks via a crafted web site that uses the HTTP server push feature with multipart responses.

CVSS2: 4
2%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1695

Mozilla Firefox before 22.0 does not properly implement certain DocShe ...

CVSS2: 5
3%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться