Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114220232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 14 793

nvd логотип

CVE-2006-6502

больше 18 лет назад

Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.

CVSS2: 7.1
EPSS: Средний
nvd логотип

CVE-2006-6507

больше 18 лет назад

Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-6503

больше 18 лет назад

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.

CVSS2: 6.8
EPSS: Средний
nvd логотип

CVE-2006-6506

больше 18 лет назад

The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed viewing services to determine browsing habits.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-6497

больше 18 лет назад

Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2006-6507

больше 18 лет назад

Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass C ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-6503

больше 18 лет назад

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird ...

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2006-6499

больше 18 лет назад

The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x befo ...

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2006-6506

больше 18 лет назад

The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-6500

больше 18 лет назад

Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5. ...

CVSS2: 6.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-6502

Use-after-free vulnerability in the LiveConnect bridge code for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to cause a denial of service (crash) via unknown vectors.

CVSS2: 7.1
17%
Средний
больше 18 лет назад
nvd логотип
CVE-2006-6507

Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass Cross-Site Scripting (XSS) protection via vectors related to a Function.prototype regression error.

CVSS2: 4.3
4%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-6503

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allows remote attackers to bypass cross-site scripting (XSS) protection by changing the src attribute of an IMG element to a javascript: URI.

CVSS2: 6.8
22%
Средний
больше 18 лет назад
nvd логотип
CVE-2006-6506

The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends the URL of the feed when requesting favicon.ico icons, which results in a privacy leak that might allow feed viewing services to determine browsing habits.

CVSS2: 4.3
3%
Низкий
больше 18 лет назад
nvd логотип
CVE-2006-6497

Multiple unspecified vulnerabilities in the layout engine for Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird before 1.5.0.9, and SeaMonkey before 1.0.7 allow remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via unknown attack vectors.

CVSS2: 6.8
13%
Средний
больше 18 лет назад
debian логотип
CVE-2006-6507

Mozilla Firefox 2.0 before 2.0.0.1 allows remote attackers to bypass C ...

CVSS2: 4.3
4%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6503

Mozilla Firefox 2.x before 2.0.0.1, 1.5.x before 1.5.0.9, Thunderbird ...

CVSS2: 6.8
22%
Средний
больше 18 лет назад
debian логотип
CVE-2006-6499

The js_dtoa function in Mozilla Firefox 2.x before 2.0.0.1, 1.5.x befo ...

CVSS2: 4.3
24%
Средний
больше 18 лет назад
debian логотип
CVE-2006-6506

The "Feed Preview" feature in Mozilla Firefox 2.0 before 2.0.0.1 sends ...

CVSS2: 4.3
3%
Низкий
больше 18 лет назад
debian логотип
CVE-2006-6500

Heap-based buffer overflow in Mozilla Firefox 2.x before 2.0.0.1, 1.5. ...

CVSS2: 6.8
38%
Средний
больше 18 лет назад

Уязвимостей на страницу


Поделиться