Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2008-5697

около 17 лет назад

The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitrary data to the clipboard via a string argument.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5513

около 17 лет назад

Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-5513

около 17 лет назад

Unspecified vulnerability in the session-restore feature in Mozilla Fi ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5512

около 17 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2008-5512

около 17 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0 ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5511

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-5511

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5510

около 17 лет назад

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-5510

около 17 лет назад

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0. ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5508

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-5697

The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitrary data to the clipboard via a string argument.

CVSS2: 4.3
5%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5513

Unspecified vulnerability in the session-restore feature in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19 allows remote attackers to bypass the same origin policy, inject content into documents associated with other domains, and conduct cross-site scripting (XSS) attacks via unknown vectors related to restoration of SessionStore data.

CVSS2: 4.3
2%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5513

Unspecified vulnerability in the session-restore feature in Mozilla Fi ...

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5512

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to run arbitrary JavaScript with chrome privileges via unknown vectors in which "page content can pollute XPCNativeWrappers."

CVSS2: 6.8
5%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5512

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0 ...

CVSS2: 6.8
5%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5511

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."

CVSS2: 4.3
2%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5511

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5510

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 ignores the '\0' escaped null character, which might allow remote attackers to bypass protection mechanisms such as sanitization routines.

CVSS2: 5
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5510

The CSS parser in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0. ...

CVSS2: 5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5508

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not properly parse URLs with leading whitespace or control characters, which might allow remote attackers to misrepresent URLs and simplify phishing attacks.

CVSS2: 4.3
2%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться