Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2008-5508

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5507

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.

CVSS2: 6
EPSS: Низкий
debian логотип

CVE-2008-5507

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 6
EPSS: Низкий
nvd логотип

CVE-2008-5506

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2008-5506

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-5505

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-5505

около 17 лет назад

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass int ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5504

около 17 лет назад

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-5504

около 17 лет назад

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arb ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5503

около 17 лет назад

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2008-5508

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5507

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allow remote attackers to bypass the same origin policy and access portions of data from another domain via a JavaScript URL that redirects to the target resource, which generates an error if the target data does not have JavaScript syntax, which can be accessed using the window.onerror DOM API.

CVSS2: 6
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5507

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 6
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5506

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy by causing the browser to issue an XMLHttpRequest to an attacker-controlled resource that uses a 302 redirect to a resource in a different domain, then reading content from the response, aka "response disclosure."

CVSS2: 6.8
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5506

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird ...

CVSS2: 6.8
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass intended privacy restrictions by using the persist attribute in an XUL element to create and access data entities that are similar to cookies.

CVSS2: 5
1%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5505

Mozilla Firefox 3.x before 3.0.5 allows remote attackers to bypass int ...

CVSS2: 5
1%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5504

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arbitrary JavaScript with chrome privileges via vectors related to the feed preview, a different vulnerability than CVE-2008-3836.

CVSS2: 7.5
4%
Низкий
около 17 лет назад
debian логотип
CVE-2008-5504

Mozilla Firefox 2.x before 2.0.0.19 allows remote attackers to run arb ...

CVSS2: 7.5
4%
Низкий
около 17 лет назад
nvd логотип
CVE-2008-5503

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
1%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться