Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2013-1695

около 13 лет назад

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME element.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2013-1694

около 13 лет назад

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Fir ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2013-1694

около 13 лет назад

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly handle the lack of a wrapper, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by leveraging unintended clearing of the wrapper cache's preserved-wrapper flag.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2013-1693

около 13 лет назад

The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1693

около 13 лет назад

The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1692

около 13 лет назад

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbi ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1692

около 13 лет назад

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1690

около 13 лет назад

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbi ...

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2013-1690

около 13 лет назад

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2013-1688

около 13 лет назад

The Profiler implementation in Mozilla Firefox before 22.0 parses untr ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2013-1695

Mozilla Firefox before 22.0 does not properly implement certain DocShell inheritance behavior for the sandbox attribute of an IFRAME element, which allows remote attackers to bypass intended access restrictions via a FRAME element within an IFRAME element.

CVSS2: 5
3%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1694

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Fir ...

CVSS2: 7.5
5%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1694

The PreserveWrapper implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 does not properly handle the lack of a wrapper, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by leveraging unintended clearing of the wrapper cache's preserved-wrapper flag.

CVSS2: 7.5
5%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1693

The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ...

CVSS2: 4.3
4%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1693

The SVG filter implementation in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allows remote attackers to read pixel values, and possibly bypass the Same Origin Policy and read text from a different domain, by observing timing differences in execution of filter code.

CVSS2: 4.3
4%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1692

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbi ...

CVSS2: 4.3
2%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1692

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not prevent the inclusion of body data in an XMLHttpRequest HEAD request, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 4.3
2%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1690

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbi ...

CVSS3: 8.8
69%
Средний
около 13 лет назад
nvd логотип
CVE-2013-1690

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

CVSS3: 8.8
69%
Средний
около 13 лет назад
debian логотип
CVE-2013-1688

The Profiler implementation in Mozilla Firefox before 22.0 parses untr ...

CVSS2: 9.3
3%
Низкий
около 13 лет назад

Уязвимостей на страницу


Поделиться