Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 16 872

debian логотип

CVE-2011-3003

почти 15 лет назад

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attac ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-3002

почти 15 лет назад

Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a resulting buffer overflow.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2011-3002

почти 15 лет назад

Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefo ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-3001

почти 15 лет назад

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-3001

почти 15 лет назад

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey b ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-3000

почти 15 лет назад

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-3000

почти 15 лет назад

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7. ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-2999

почти 15 лет назад

Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-2999

почти 15 лет назад

Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6. ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-2997

почти 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-3003

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 allow remote attac ...

CVSS2: 10
4%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3002

Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox before 7.0 and SeaMonkey before 2.4, does not validate the return value of a GrowAtomTable function call, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a memory-allocation error and a resulting buffer overflow.

CVSS2: 9.3
3%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3002

Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefo ...

CVSS2: 9.3
3%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3001

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not prevent manual add-on installation in response to the holding of the Enter key, which allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that triggers an unspecified internal error.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3001

Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey b ...

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3000

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 do not properly handle HTTP responses that contain multiple Location, Content-Length, or Content-Disposition headers, which makes it easier for remote attackers to conduct HTTP response splitting attacks via crafted header values.

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3000

Mozilla Firefox before 3.6.23 and 4.x through 6, Thunderbird before 7. ...

CVSS2: 4.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2999

Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6.0, and SeaMonkey before 2.3 do not properly handle "location" as the name of a frame, which allows remote attackers to bypass the Same Origin Policy via a crafted web site, a different vulnerability than CVE-2010-0170.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2999

Mozilla Firefox before 3.6.23 and 4.x through 5, Thunderbird before 6. ...

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2997

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
5%
Низкий
почти 15 лет назад

Уязвимостей на страницу


Поделиться