Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

ubuntu логотип

CVE-2009-0652

почти 17 лет назад

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

CVSS2: 5.8
EPSS: Низкий
redhat логотип

CVE-2009-0652

почти 17 лет назад

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-0358

около 17 лет назад

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.

CVSS2: 3.3
EPSS: Низкий
debian логотип

CVE-2009-0358

около 17 лет назад

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) n ...

CVSS2: 3.3
EPSS: Низкий
nvd логотип

CVE-2009-0357

около 17 лет назад

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2009-0357

около 17 лет назад

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not proper ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2009-0356

около 17 лет назад

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs. NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2009-0356

около 17 лет назад

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the ( ...

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2009-0355

около 17 лет назад

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.

CVSS2: 5.4
EPSS: Низкий
debian логотип

CVE-2009-0355

около 17 лет назад

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox befor ...

CVSS2: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2009-0652

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

CVSS2: 5.8
2%
Низкий
почти 17 лет назад
redhat логотип
CVE-2009-0652

The Internationalized Domain Names (IDN) blacklist in Mozilla Firefox 3.0.6 and other versions before 3.0.9; Thunderbird before 2.0.0.21; and SeaMonkey before 1.1.15 does not include box-drawing characters, which allows remote attackers to spoof URLs and conduct phishing attacks, as demonstrated by homoglyphs of the / (slash) and ? (question mark) characters in a subdomain of a .cn domain name, a different vulnerability than CVE-2005-0233. NOTE: some third parties claim that 3.0.6 is not affected, but much older versions perhaps are affected.

CVSS2: 4.3
2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-0358

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) no-store and (2) no-cache Cache-Control directives, which allows local users to obtain sensitive information by using the (a) back button or (b) history list of the victim's browser, as demonstrated by reading the response page of an https POST request.

CVSS2: 3.3
0%
Низкий
около 17 лет назад
debian логотип
CVE-2009-0358

Mozilla Firefox 3.x before 3.0.6 does not properly implement the (1) n ...

CVSS2: 3.3
0%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-0357

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not properly restrict access from web pages to the (1) Set-Cookie and (2) Set-Cookie2 HTTP response headers, which allows remote attackers to obtain sensitive information from cookies via XMLHttpRequest calls, related to the HTTPOnly protection mechanism.

CVSS2: 5
1%
Низкий
около 17 лет назад
debian логотип
CVE-2009-0357

Mozilla Firefox before 3.0.6 and SeaMonkey before 1.1.15 do not proper ...

CVSS2: 5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-0356

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the (1) about:plugins and (2) about:config URIs from .desktop files, which allows user-assisted remote attackers to bypass the Same Origin Policy and execute arbitrary code with chrome privileges via vectors involving the URL field in a Desktop Entry section of a .desktop file, related to representation of about: URIs as jar:file:// URIs. NOTE: this issue exists because of an incomplete fix for CVE-2008-4582.

CVSS2: 5.1
1%
Низкий
около 17 лет назад
debian логотип
CVE-2009-0356

Mozilla Firefox before 3.0.6 and SeaMonkey do not block links to the ( ...

CVSS2: 5.1
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-0355

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox before 3.0.6 does not block changes of INPUT elements to type="file" during tab restoration, which allows user-assisted remote attackers to read arbitrary files on a client machine via a crafted INPUT element.

CVSS2: 5.4
2%
Низкий
около 17 лет назад
debian логотип
CVE-2009-0355

components/sessionstore/src/nsSessionStore.js in Mozilla Firefox befor ...

CVSS2: 5.4
2%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться