Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

redhat логотип

CVE-2008-4582

больше 17 лет назад

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

EPSS: Средний
nvd логотип

CVE-2008-4324

больше 17 лет назад

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-4324

больше 17 лет назад

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Window ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2008-4324

больше 17 лет назад

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-4069

больше 17 лет назад

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-4069

больше 17 лет назад

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey befor ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-4068

больше 17 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2008-4068

больше 17 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2008-4067

больше 17 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-4067

больше 17 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2008-4582

Mozilla Firefox 3.0.1 through 3.0.3, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13, when running on Windows, do not properly identify the context of Windows .url shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy and obtain sensitive information via an HTML document that is directly accessible through a filesystem, as demonstrated by documents in (1) local folders, (2) Windows share folders, and (3) RAR archives, and as demonstrated by IFRAMEs referencing shortcuts that point to (a) about:cache?device=memory and (b) about:cache?device=disk, a variant of CVE-2008-2810.

36%
Средний
больше 17 лет назад
nvd логотип
CVE-2008-4324

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

CVSS2: 5
7%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-4324

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Window ...

CVSS2: 5
7%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-4324

The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a series of keypress, click, onkeydown, onkeyup, onmousedown, and onmouseup events. NOTE: it was later reported that Firefox 3.0.2 on Mac OS X 10.5 is also affected.

CVSS2: 5
7%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-4069

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to read uninitialized memory, and possibly obtain sensitive information in opportunistic circumstances, via a crafted XBM image file.

CVSS2: 5
1%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-4069

The XBM decoder in Mozilla Firefox before 2.0.0.17 and SeaMonkey befor ...

CVSS2: 5
1%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-4068

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.

CVSS2: 7.8
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-4068

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 7.8
0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-4067

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.

CVSS2: 4.3
2%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-4067

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 4.3
2%
Низкий
больше 17 лет назад

Уязвимостей на страницу


Поделиться