Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 16 888

debian логотип

CVE-2012-0475

больше 14 лет назад

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and Se ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-0474

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Universal XSS (UXSS)."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0474

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the docshell implementatio ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0473

больше 14 лет назад

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-0473

больше 14 лет назад

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-0472

больше 14 лет назад

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2012-0472

больше 14 лет назад

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, F ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2012-0471

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0471

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x throug ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0470

больше 14 лет назад

Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly execute arbitrary code by leveraging the use of "different number systems."

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-0475

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and Se ...

CVSS2: 2.6
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0474

Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Universal XSS (UXSS)."

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0474

Cross-site scripting (XSS) vulnerability in the docshell implementatio ...

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0473

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.

CVSS2: 5
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0473

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x ...

CVSS2: 5
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0472

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 9.3
4%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0472

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, F ...

CVSS2: 9.3
4%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0471

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0471

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x throug ...

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0470

Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly execute arbitrary code by leveraging the use of "different number systems."

CVSS2: 10
10%
Средний
больше 14 лет назад

Уязвимостей на страницу


Поделиться