Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

128129130131132133134135136137138139202420252026

Недавние уязвимости Mozilla Firefox

Количество 14 600

redhat логотип

CVE-2005-1532

около 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

EPSS: Средний
nvd логотип

CVE-2005-1575

около 20 лет назад

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-1575

около 20 лет назад

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1576

около 20 лет назад

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-1532

около 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-1531

около 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-1576

около 20 лет назад

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-1532

около 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly li ...

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2005-1531

около 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-1531

около 20 лет назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2005-1532

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

17%
Средний
около 20 лет назад
nvd логотип
CVE-2005-1575

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows allows remote attackers to hide the real file types of downloaded files via the Content-Type HTTP header and a filename containing whitespace, dots, or ASCII byte 160.

CVSS2: 5
0%
Низкий
около 20 лет назад
debian логотип
CVE-2005-1575

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 5
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-1576

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.

CVSS2: 2.6
0%
Низкий
около 20 лет назад
nvd логотип
CVE-2005-1532

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
17%
Средний
около 20 лет назад
nvd логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
2%
Низкий
около 20 лет назад
debian логотип
CVE-2005-1576

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 2.6
0%
Низкий
около 20 лет назад
debian логотип
CVE-2005-1532

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly li ...

CVSS2: 7.5
17%
Средний
около 20 лет назад
debian логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly ...

CVSS2: 7.5
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
2%
Низкий
около 20 лет назад

Уязвимостей на страницу


Поделиться