Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114220232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 14 782

nvd логотип

CVE-2007-5415

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-5414

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-5414

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0 ...

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-5415

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-5415

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-5414

почти 18 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2007-5341

почти 18 лет назад

Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2017-02020

почти 18 лет назад

Уязвимость отладчика сценария Venkman браузера Firefox, позволяющая нарушителю выполнить произвольный код

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2007-5274

почти 18 лет назад

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2007-5274

почти 18 лет назад

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earli ...

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2007-5415

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.

CVSS2: 4.3
0%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-5414

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

CVSS2: 2.6
0%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-5414

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0 ...

CVSS2: 2.6
0%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-5415

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when ...

CVSS2: 4.3
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-5415

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses '/' (slash) characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5414.

CVSS2: 4.3
0%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2007-5414

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

CVSS2: 2.6
0%
Низкий
почти 18 лет назад
redhat логотип
CVE-2007-5341

Remote code execution in the Venkman script debugger in Mozilla Firefox before 2.0.0.8.

CVSS3: 9.8
2%
Низкий
почти 18 лет назад
fstec логотип
BDU:2017-02020

Уязвимость отладчика сценария Venkman браузера Firefox, позволяющая нарушителю выполнить произвольный код

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2007-5274

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earlier, JDK and JRE 5.0 Update 12 and earlier, SDK and JRE 1.4.2_15 and earlier, and SDK and JRE 1.3.1_20 and earlier, when Firefox or Opera is used, allows remote attackers to violate the security model for JavaScript outbound connections via a multi-pin DNS rebinding attack dependent on the LiveConnect API, in which JavaScript download relies on DNS resolution by the browser, but JavaScript socket operations rely on separate DNS resolution by a Java Virtual Machine (JVM), a different issue than CVE-2007-5273. NOTE: this is similar to CVE-2007-5232.

CVSS2: 2.6
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2007-5274

Sun Java Runtime Environment (JRE) in JDK and JRE 6 Update 2 and earli ...

CVSS2: 2.6
5%
Низкий
почти 18 лет назад

Уязвимостей на страницу


Поделиться