Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2008-5022

около 17 лет назад

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2008-5022

около 17 лет назад

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x befor ...

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2008-5021

около 17 лет назад

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2008-5021

около 17 лет назад

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1 ...

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2008-5019

около 17 лет назад

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2008-5019

около 17 лет назад

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2. ...

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2008-5018

около 17 лет назад

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2008-5018

около 17 лет назад

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2008-5017

около 17 лет назад

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2008-5017

около 17 лет назад

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Moz ...

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

CVSS2: 7.5
13%
Средний
около 17 лет назад
debian логотип
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x befor ...

CVSS2: 7.5
13%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVSS2: 9.3
25%
Средний
около 17 лет назад
debian логотип
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1 ...

CVSS2: 9.3
25%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5019

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

CVSS2: 4.3
13%
Средний
около 17 лет назад
debian логотип
CVE-2008-5019

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2. ...

CVSS2: 4.3
13%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5018

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.

CVSS2: 10
20%
Средний
около 17 лет назад
debian логотип
CVE-2008-5018

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x ...

CVSS2: 10
20%
Средний
около 17 лет назад
nvd логотип
CVE-2008-5017

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors.

CVSS2: 10
17%
Средний
около 17 лет назад
debian логотип
CVE-2008-5017

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Moz ...

CVSS2: 10
17%
Средний
около 17 лет назад

Уязвимостей на страницу


Поделиться