Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2009-3375

больше 16 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-3375

больше 16 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-3374

больше 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3374

больше 16 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3373

больше 16 лет назад

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2009-3373

больше 16 лет назад

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2009-3372

больше 16 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2009-3372

больше 16 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-3371

больше 16 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-3371

больше 16 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 all ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2009-3375

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

CVSS2: 4.3
0%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3375

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x ...

CVSS2: 4.3
0%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3373

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
13%
Средний
больше 16 лет назад
debian логотип
CVE-2009-3373

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox ...

CVSS2: 10
13%
Средний
больше 16 лет назад
nvd логотип
CVE-2009-3372

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.

CVSS2: 9.3
2%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3372

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
2%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-3371

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

CVSS2: 10
3%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-3371

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 all ...

CVSS2: 10
3%
Низкий
больше 16 лет назад

Уязвимостей на страницу


Поделиться