Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2013-0795

больше 13 лет назад

The System Only Wrapper (SOW) implementation in Mozilla Firefox before ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2013-0795

больше 13 лет назад

The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 does not prevent use of the cloneNode method for cloning a protected node, which allows remote attackers to bypass the Same Origin Policy or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2013-0794

больше 13 лет назад

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent o ...

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2013-0794

больше 13 лет назад

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2013-0793

больше 13 лет назад

Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbi ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0793

больше 13 лет назад

Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over navigation timing.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-0792

больше 13 лет назад

Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_ ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2013-0792

больше 13 лет назад

Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2013-0791

больше 13 лет назад

The CERT_DecodeCertPackage function in Mozilla Network Security Servic ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2013-0791

больше 13 лет назад

The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2013-0795

The System Only Wrapper (SOW) implementation in Mozilla Firefox before ...

CVSS2: 10
3%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0795

The System Only Wrapper (SOW) implementation in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 does not prevent use of the cloneNode method for cloning a protected node, which allows remote attackers to bypass the Same Origin Policy or possibly execute arbitrary JavaScript code with chrome privileges via a crafted web site.

CVSS2: 10
3%
Низкий
больше 13 лет назад
debian логотип
CVE-2013-0794

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent o ...

CVSS2: 5.8
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0794

Mozilla Firefox before 20.0 and SeaMonkey before 2.17 do not prevent origin spoofing of tab-modal dialogs, which allows remote attackers to conduct phishing attacks via a crafted web site.

CVSS2: 5.8
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2013-0793

Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbi ...

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0793

Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, and SeaMonkey before 2.17 do not ensure the correctness of the address bar during history navigation, which allows remote attackers to conduct cross-site scripting (XSS) attacks or phishing attacks by leveraging control over navigation timing.

CVSS2: 4.3
2%
Низкий
больше 13 лет назад
debian логотип
CVE-2013-0792

Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_ ...

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0792

Mozilla Firefox before 20.0 and SeaMonkey before 2.17, when gfx.color_management.enablev4 is used, do not properly handle color profiles during PNG rendering, which allows remote attackers to obtain sensitive information from process memory or cause a denial of service (memory corruption) via a grayscale PNG image.

CVSS2: 4.3
1%
Низкий
больше 13 лет назад
debian логотип
CVE-2013-0791

The CERT_DecodeCertPackage function in Mozilla Network Security Servic ...

CVSS2: 5
5%
Низкий
больше 13 лет назад
nvd логотип
CVE-2013-0791

The CERT_DecodeCertPackage function in Mozilla Network Security Services (NSS), as used in Mozilla Firefox before 20.0, Firefox ESR 17.x before 17.0.5, Thunderbird before 17.0.5, Thunderbird ESR 17.x before 17.0.5, SeaMonkey before 2.17, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and memory corruption) via a crafted certificate.

CVSS2: 5
5%
Низкий
больше 13 лет назад

Уязвимостей на страницу


Поделиться