Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

debian логотип

CVE-2012-3975

почти 14 лет назад

The DOMParser component in Mozilla Firefox before 15.0, Thunderbird be ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-3974

почти 14 лет назад

Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.

CVSS2: 6.9
EPSS: Низкий
debian логотип

CVE-2012-3974

почти 14 лет назад

Untrusted search path vulnerability in the installer in Mozilla Firefo ...

CVSS2: 6.9
EPSS: Низкий
nvd логотип

CVE-2012-3973

почти 14 лет назад

The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging the presence of the HTTPMonitor extension and connecting to that service through the HTTPMonitor port.

CVSS2: 7.6
EPSS: Низкий
debian логотип

CVE-2012-3973

почти 14 лет назад

The debugger in the developer-tools subsystem in Mozilla Firefox befor ...

CVSS2: 7.6
EPSS: Низкий
nvd логотип

CVE-2012-3972

почти 14 лет назад

The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-3972

почти 14 лет назад

The format-number functionality in the XSLT implementation in Mozilla ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-3971

почти 14 лет назад

Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the (1) Silf::readClassMap and (2) Pass::readPass functions.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2012-3971

почти 14 лет назад

Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla F ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2012-3970

почти 14 лет назад

Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving movement of a requiredFeatures attribute from one SVG document to another.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-3975

The DOMParser component in Mozilla Firefox before 15.0, Thunderbird be ...

CVSS2: 4.3
2%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3974

Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.

CVSS2: 6.9
0%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3974

Untrusted search path vulnerability in the installer in Mozilla Firefo ...

CVSS2: 6.9
0%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3973

The debugger in the developer-tools subsystem in Mozilla Firefox before 15.0, when remote debugging is disabled, does not properly restrict access to the remote-debugging service, which allows remote attackers to execute arbitrary code by leveraging the presence of the HTTPMonitor extension and connecting to that service through the HTTPMonitor port.

CVSS2: 7.6
5%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3973

The debugger in the developer-tools subsystem in Mozilla Firefox befor ...

CVSS2: 7.6
5%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3972

The format-number functionality in the XSLT implementation in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to obtain sensitive information via unspecified vectors that trigger a heap-based buffer over-read.

CVSS2: 5
4%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3972

The format-number functionality in the XSLT implementation in Mozilla ...

CVSS2: 5
4%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3971

Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla Firefox before 15.0, Thunderbird before 15.0, and SeaMonkey before 2.12, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the (1) Silf::readClassMap and (2) Pass::readPass functions.

CVSS2: 10
5%
Низкий
почти 14 лет назад
debian логотип
CVE-2012-3971

Summer Institute of Linguistics (SIL) Graphite 2, as used in Mozilla F ...

CVSS2: 10
5%
Низкий
почти 14 лет назад
nvd логотип
CVE-2012-3970

Use-after-free vulnerability in the nsTArray_base::Length function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving movement of a requiredFeatures attribute from one SVG document to another.

CVSS2: 10
5%
Низкий
почти 14 лет назад

Уязвимостей на страницу


Поделиться