Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2009-2465

больше 16 лет назад

Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2465

больше 16 лет назад

Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers t ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2464

больше 16 лет назад

The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2009-2464

больше 16 лет назад

The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozil ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2009-2463

больше 16 лет назад

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2463

больше 16 лет назад

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base6 ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2462

больше 16 лет назад

The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2462

больше 16 лет назад

The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird al ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2009-2466

больше 16 лет назад

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2009-2469

больше 16 лет назад

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2009-2465

Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers to cause a denial of service (memory corruption and application crash) or execute arbitrary code via vectors involving double frame construction, related to (1) nsHTMLContentSink.cpp, (2) nsXMLContentSink.cpp, and (3) nsPresShell.cpp, and the nsSubDocumentFrame::Reflow function.

CVSS2: 10
4%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2465

Mozilla Firefox before 3.0.12 and Thunderbird allow remote attackers t ...

CVSS2: 10
4%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2464

The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to loading multiple RDF files in a XUL tree element.

CVSS2: 10
18%
Средний
больше 16 лет назад
debian логотип
CVE-2009-2464

The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozil ...

CVSS2: 10
18%
Средний
больше 16 лет назад
nvd логотип
CVE-2009-2463

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base64Encode functions in nsprpub/lib/libc/src/base64.c in Mozilla Firefox before 3.0.12, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors that trigger buffer overflows.

CVSS2: 10
5%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2463

Multiple integer overflows in the (1) PL_Base64Decode and (2) PL_Base6 ...

CVSS2: 10
5%
Низкий
больше 16 лет назад
nvd логотип
CVE-2009-2462

The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) the frame chain and synchronous events, (2) a SetMayHaveFrame assertion and nsCSSFrameConstructor::CreateFloatingLetterFrame, (3) nsCSSFrameConstructor::ConstructFrame, (4) the child list and initial reflow, (5) GetLastSpecialSibling, (6) nsFrameManager::GetPrimaryFrameFor and MathML, (7) nsFrame::GetBoxAscent, (8) nsCSSFrameConstructor::AdjustParentFrame, (9) nsDOMOfflineResourceList, and (10) nsContentUtils::ComparePosition.

CVSS2: 10
3%
Низкий
больше 16 лет назад
debian логотип
CVE-2009-2462

The browser engine in Mozilla Firefox before 3.0.12 and Thunderbird al ...

CVSS2: 10
3%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-2466

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.

CVSS2: 10
6%
Низкий
больше 16 лет назад
ubuntu логотип
CVE-2009-2469

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.

CVSS2: 10
4%
Низкий
больше 16 лет назад

Уязвимостей на страницу


Поделиться