Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 156

debian логотип

CVE-2008-5052

около 17 лет назад

The AppendAttributeValue function in the JavaScript engine in Mozilla ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2008-5024

около 17 лет назад

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-5024

около 17 лет назад

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunder ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5023

около 17 лет назад

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2008-5023

около 17 лет назад

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1 ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2008-5022

около 17 лет назад

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2008-5022

около 17 лет назад

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x befor ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2008-5021

около 17 лет назад

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2008-5021

около 17 лет назад

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1 ...

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2008-5019

около 17 лет назад

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2008-5052

The AppendAttributeValue function in the JavaScript engine in Mozilla ...

CVSS2: 10
23%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5024

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 do not properly escape quote characters used for XML processing, which allows remote attackers to conduct XML injection attacks via the default namespace in an E4X document.

CVSS2: 7.5
7%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5024

Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunder ...

CVSS2: 7.5
7%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5023

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.

CVSS2: 7.5
18%
Средний
около 17 лет назад
debian логотип
CVE-2008-5023

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1 ...

CVSS2: 7.5
18%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

CVSS2: 7.5
13%
Средний
около 17 лет назад
debian логотип
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x befor ...

CVSS2: 7.5
13%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVSS2: 9.3
25%
Средний
около 17 лет назад
debian логотип
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1 ...

CVSS2: 9.3
25%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5019

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

CVSS2: 4.3
13%
Средний
около 17 лет назад

Уязвимостей на страницу


Поделиться