Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

debian логотип

CVE-2007-1004

больше 18 лет назад

Mozilla Firefox might allow remote attackers to conduct spoofing and p ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-1004

больше 18 лет назад

Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-0981

больше 18 лет назад

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2007-0981

больше 18 лет назад

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x befo ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2007-0981

больше 18 лет назад

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2007-0896

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-0896

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-0896

больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2007-5947

почти 19 лет назад

The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.

EPSS: Низкий
nvd логотип

CVE-2007-0802

почти 19 лет назад

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.

CVSS2: 6.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2007-1004

Mozilla Firefox might allow remote attackers to conduct spoofing and p ...

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-1004

Mozilla Firefox might allow remote attackers to conduct spoofing and phishing attacks by writing to an about:blank tab and overlaying the location bar.

CVSS2: 4.3
1%
Низкий
больше 18 лет назад
nvd логотип
CVE-2007-0981

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

CVSS2: 7.5
18%
Средний
больше 18 лет назад
debian логотип
CVE-2007-0981

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x befo ...

CVSS2: 7.5
18%
Средний
больше 18 лет назад
ubuntu логотип
CVE-2007-0981

Mozilla based browsers, including Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8, allow remote attackers to bypass the same origin policy, steal cookies, and conduct other attacks by writing a URI with a null byte to the hostname (location.hostname) DOM property, due to interactions with DNS resolver code.

CVSS2: 7.5
18%
Средний
больше 18 лет назад
nvd логотип
CVE-2007-0896

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

CVSS2: 4.3
9%
Низкий
больше 18 лет назад
debian логотип
CVE-2007-0896

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10 ...

CVSS2: 4.3
9%
Низкий
больше 18 лет назад
ubuntu логотип
CVE-2007-0896

Cross-site scripting (XSS) vulnerability in the (1) Sage before 1.3.10, and (2) Sage++ extensions for Firefox, allows remote attackers to inject arbitrary web script or HTML via a "<SCRIPT/=''SRC='" sequence in an RSS feed, a different vulnerability than CVE-2006-4712.

CVSS2: 4.3
9%
Низкий
больше 18 лет назад
redhat логотип
CVE-2007-5947

The jar protocol handler in Mozilla Firefox before 2.0.0.10 and SeaMonkey before 1.1.7 retrieves the inner URL regardless of its MIME type, and considers HTML documents within a jar archive to have the same origin as the inner URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a jar: URI.

8%
Низкий
почти 19 лет назад
nvd логотип
CVE-2007-0802

Mozilla Firefox 2.0.0.1 allows remote attackers to bypass the Phishing Protection mechanism by adding certain characters to the end of the domain name, as demonstrated by the "." and "/" characters, which is not caught by the Phishing List blacklist filter.

CVSS2: 6.4
1%
Низкий
почти 19 лет назад

Уязвимостей на страницу


Поделиться