Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

nvd логотип

CVE-2008-4061

около 17 лет назад

Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attribute, related to the layout engine.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2008-4061

около 17 лет назад

Integer overflow in the MathML component in Mozilla Firefox before 2.0 ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-4060

около 17 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-4060

около 17 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird befo ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4059

около 17 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-4059

около 17 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remo ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4058

около 17 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-4058

около 17 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x bef ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3837

около 17 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2008-3837

около 17 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey be ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-4061

Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attribute, related to the layout engine.

CVSS2: 10
3%
Низкий
около 17 лет назад
debian логотип
CVE-2008-4061

Integer overflow in the MathML component in Mozilla Firefox before 2.0 ...

CVSS2: 10
3%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

CVSS2: 7.5
2%
Низкий
около 17 лет назад
debian логотип
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird befo ...

CVSS2: 7.5
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
2%
Низкий
около 17 лет назад
debian логотип
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remo ...

CVSS2: 7.5
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-4058

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to (1) chrome XBL and (2) chrome JS.

CVSS2: 7.5
2%
Низкий
около 17 лет назад
debian логотип
CVE-2008-4058

The XPConnect component in Mozilla Firefox before 2.0.0.17 and 3.x bef ...

CVSS2: 7.5
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-3837

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

CVSS2: 9.3
3%
Низкий
около 17 лет назад
debian логотип
CVE-2008-3837

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey be ...

CVSS2: 9.3
3%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться