Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

nvd логотип

CVE-2007-2870

больше 18 лет назад

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-2871

больше 18 лет назад

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2007-2869

больше 18 лет назад

The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2007-2867

больше 18 лет назад

Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issues.

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2007-2871

больше 18 лет назад

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaM ...

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2007-2867

больше 18 лет назад

Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5. ...

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2007-1362

больше 18 лет назад

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaM ...

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2007-2870

больше 18 лет назад

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaM ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-2869

больше 18 лет назад

The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12 ...

CVSS2: 4.3
EPSS: Средний
debian логотип

CVE-2007-2868

больше 18 лет назад

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox ...

CVSS2: 9.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2007-2870

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to bypass the same-origin policy and conduct cross-site scripting (XSS) and other attacks by using the addEventListener method to add an event listener for a site, which is executed in the context of that site.

CVSS2: 4.3
8%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-2871

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to spoof or hide the browser chrome, such as the location bar, by placing XUL popups outside of the browser's content pane. NOTE: this issue can be leveraged for phishing and other attacks.

CVSS2: 4.3
16%
Средний
больше 18 лет назад
nvd логотип
CVE-2007-2869

The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12, 2.x before 2.0.0.4, and possibly earlier versions, allows remote attackers to cause a denial of service (persistent temporary CPU consumption) via a large number of characters in a submitted form.

CVSS2: 4.3
16%
Средний
больше 18 лет назад
nvd логотип
CVE-2007-2867

Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, Thunderbird 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2 allow remote attackers to cause a denial of service (crash) via vectors related to dangling pointers, heap corruption, signed/unsigned, and other issues.

CVSS2: 9.3
31%
Средний
больше 18 лет назад
debian логотип
CVE-2007-2871

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaM ...

CVSS2: 4.3
16%
Средний
больше 18 лет назад
debian логотип
CVE-2007-2867

Multiple vulnerabilities in the layout engine for Mozilla Firefox 1.5. ...

CVSS2: 9.3
31%
Средний
больше 18 лет назад
debian логотип
CVE-2007-1362

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaM ...

CVSS2: 4.3
45%
Средний
больше 18 лет назад
debian логотип
CVE-2007-2870

Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaM ...

CVSS2: 4.3
8%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-2869

The form autocomplete feature in Mozilla Firefox 1.5.x before 1.5.0.12 ...

CVSS2: 4.3
16%
Средний
больше 18 лет назад
debian логотип
CVE-2007-2868

Multiple vulnerabilities in the JavaScript engine for Mozilla Firefox ...

CVSS2: 9.3
38%
Средний
больше 18 лет назад

Уязвимостей на страницу


Поделиться