Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

redhat логотип

CVE-2012-4930

почти 14 лет назад

The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-3980

почти 14 лет назад

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2012-3980

почти 14 лет назад

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x befor ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2012-3979

почти 14 лет назад

Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-3979

почти 14 лет назад

Mozilla Firefox before 15.0 on Android does not properly implement uns ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-3978

почти 14 лет назад

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-3978

почти 14 лет назад

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Fire ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-3976

почти 14 лет назад

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-3976

почти 14 лет назад

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-3975

почти 14 лет назад

The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2012-4930

The SPDY protocol 3 and earlier, as used in Mozilla Firefox, Google Chrome, and other products, can perform TLS encryption of compressed data without properly obfuscating the length of the unencrypted data, which allows man-in-the-middle attackers to obtain plaintext HTTP headers by observing length differences during a series of guesses in which a string in an HTTP request potentially matches an unknown string in an HTTP header, aka a "CRIME" attack.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3980

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a crafted web site that injects this code and triggers an eval operation.

CVSS2: 9.3
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3980

The web console in Mozilla Firefox before 15.0, Firefox ESR 10.x befor ...

CVSS2: 9.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3979

Mozilla Firefox before 15.0 on Android does not properly implement unspecified callers of the __android_log_print function, which allows remote attackers to execute arbitrary code via a crafted web page that calls the JavaScript dump function.

CVSS2: 6.8
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3979

Mozilla Firefox before 15.0 on Android does not properly implement uns ...

CVSS2: 6.8
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3978

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 does not properly follow the security model of the location object, which allows remote attackers to bypass intended content-loading restrictions or possibly have unspecified other impact via vectors involving chrome code.

CVSS2: 6.8
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3978

The nsLocation::CheckURL function in Mozilla Firefox before 15.0, Fire ...

CVSS2: 6.8
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3976

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMonkey before 2.12 do not properly handle onLocationChange events during navigation between different https sites, which allows remote attackers to spoof the X.509 certificate information in the address bar via a crafted web page.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3976

Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, and SeaMo ...

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3975

The DOMParser component in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12 loads subresources during parsing of text/html data within an extension, which allows remote attackers to obtain sensitive information by providing crafted data to privileged extension code.

CVSS2: 4.3
2%
Низкий
почти 14 лет назад

Уязвимостей на страницу


Поделиться