Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2008-3836

больше 17 лет назад

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-3836

больше 17 лет назад

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3835

больше 17 лет назад

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-3835

больше 17 лет назад

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox befor ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-0016

больше 17 лет назад

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2008-0016

больше 17 лет назад

Stack-based buffer overflow in the URL parsing implementation in Mozil ...

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2008-4059

больше 17 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2008-4063

больше 17 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-0016

больше 17 лет назад

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2008-4060

больше 17 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-3836

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3836

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers ...

CVSS2: 7.5
3%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-3835

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.

CVSS2: 7.5
0%
Низкий
больше 17 лет назад
debian логотип
CVE-2008-3835

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox befor ...

CVSS2: 7.5
0%
Низкий
больше 17 лет назад
nvd логотип
CVE-2008-0016

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

CVSS2: 10
47%
Средний
больше 17 лет назад
debian логотип
CVE-2008-0016

Stack-based buffer overflow in the URL parsing implementation in Mozil ...

CVSS2: 10
47%
Средний
больше 17 лет назад
ubuntu логотип
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
2%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-4063

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.

CVSS2: 9.3
3%
Низкий
больше 17 лет назад
ubuntu логотип
CVE-2008-0016

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

CVSS2: 10
47%
Средний
больше 17 лет назад
ubuntu логотип
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

CVSS2: 7.5
2%
Низкий
больше 17 лет назад

Уязвимостей на страницу


Поделиться