Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 156

nvd логотип

CVE-2008-5505

почти 17 лет назад

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-5505

почти 17 лет назад

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass int ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5504

почти 17 лет назад

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-5504

почти 17 лет назад

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arb ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5503

почти 17 лет назад

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-5503

почти 17 лет назад

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.1 ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-5502

почти 17 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-5502

почти 17 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5501

почти 17 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-5501

почти 17 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

CVSS2: 5
1%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass int ...

CVSS2: 5
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-5504

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

CVSS2: 7.5
4%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-5504

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arb ...

CVSS2: 7.5
4%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-5503

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-5503

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.1 ...

CVSS2: 2.6
1%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-5502

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

CVSS2: 5
4%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-5502

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
4%
Низкий
почти 17 лет назад
nvd логотип
CVE-2008-5501

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

CVSS2: 5
5%
Низкий
почти 17 лет назад
debian логотип
CVE-2008-5501

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
5%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться