Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

128129130131132133134135136137138139202420252026

Недавние уязвимости Mozilla Firefox

Количество 14 600

redhat логотип

CVE-2005-2114

почти 20 лет назад

Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.

EPSS: Низкий
nvd логотип

CVE-2005-1937

около 20 лет назад

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-1937

около 20 лет назад

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote at ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-1937

около 20 лет назад

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2005-2268

около 20 лет назад

Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

EPSS: Низкий
redhat логотип

CVE-2005-1937

около 20 лет назад

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.

EPSS: Низкий
nvd логотип

CVE-2005-0150

около 20 лет назад

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-0150

около 20 лет назад

Firefox before 1.0 allows the user to store a (1) javascript: or (2) d ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0150

около 20 лет назад

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2005-1531

около 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2005-2114

Mozilla 1.7.8, Firefox 1.0.4, Camino 0.8.4, Netscape 8.0.2, and K-Meleon 0.9, and possibly other products that use the Gecko engine, allow remote attackers to cause a denial of service (application crash) via JavaScript that repeatedly calls an empty function.

4%
Низкий
почти 20 лет назад
nvd логотип
CVE-2005-1937

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.

CVSS2: 2.6
1%
Низкий
около 20 лет назад
debian логотип
CVE-2005-1937

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote at ...

CVSS2: 2.6
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-1937

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.

CVSS2: 2.6
1%
Низкий
около 20 лет назад
redhat логотип
CVE-2005-2268

Firefox before 1.0.5 and Mozilla before 1.7.9 does not clearly associate a Javascript dialog box with the web page that generated it, which allows remote attackers to spoof a dialog box from a trusted site and facilitates phishing attacks, aka the "Dialog Origin Spoofing Vulnerability."

2%
Низкий
около 20 лет назад
redhat логотип
CVE-2005-1937

A regression error in Firefox 1.0.3 and Mozilla 1.7.7 allows remote attackers to inject arbitrary Javascript from one page into the frameset of another site, aka the frame injection spoofing vulnerability, a re-introduction of a vulnerability that was originally identified and addressed by CVE-2004-0718.

1%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-0150

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

CVSS2: 5
1%
Низкий
около 20 лет назад
debian логотип
CVE-2005-0150

Firefox before 1.0 allows the user to store a (1) javascript: or (2) d ...

CVSS2: 5
1%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-0150

Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.

CVSS2: 5
1%
Низкий
около 20 лет назад
redhat логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

2%
Низкий
около 20 лет назад

Уязвимостей на страницу


Поделиться