Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2013-1674

около 13 лет назад

Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox E ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2013-1674

около 13 лет назад

Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code via vectors involving an onresize event during the playing of a video.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2013-1673

около 13 лет назад

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not ...

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2013-1673

около 13 лет назад

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2013-1672

около 13 лет назад

The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefo ...

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2013-1672

около 13 лет назад

The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2013-1671

около 13 лет назад

Mozilla Firefox before 21.0 does not properly implement the INPUT elem ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-1671

около 13 лет назад

Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-1670

около 13 лет назад

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox befo ...

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2013-1670

около 13 лет назад

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-1674

Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox E ...

CVSS2: 9.3
6%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1674

Use-after-free vulnerability in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 allows remote attackers to execute arbitrary code via vectors involving an onresize event during the playing of a video.

CVSS2: 9.3
6%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1673

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not ...

CVSS2: 6.9
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1673

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."

CVSS2: 6.9
0%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1672

The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefo ...

CVSS2: 6.9
0%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1672

The Mozilla Maintenance Service in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 on Windows allows local users to bypass integrity verification and gain privileges via vectors involving junctions.

CVSS2: 6.9
0%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1671

Mozilla Firefox before 21.0 does not properly implement the INPUT elem ...

CVSS2: 4.3
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-1671

Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.

CVSS2: 4.3
1%
Низкий
около 13 лет назад
debian логотип
CVE-2013-1670

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox befo ...

CVSS2: 4.3
11%
Средний
около 13 лет назад
nvd логотип
CVE-2013-1670

The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 does not prevent acquisition of chrome privileges during calls to content level constructors, which allows remote attackers to bypass certain read-only restrictions and conduct cross-site scripting (XSS) attacks via a crafted web site.

CVSS2: 4.3
11%
Средний
около 13 лет назад

Уязвимостей на страницу


Поделиться