Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

redhat логотип

CVE-2012-1952

около 14 лет назад

The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly perform a cast of a frame variable during processing of mixed row-group and column-group frames, which might allow remote attackers to execute arbitrary code via a crafted web site.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2012-1964

около 14 лет назад

The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.10 does not properly handle attempted clickjacking of the about:certerror page, which allows man-in-the-middle attackers to trick users into adding an unintended exception via an IFRAME element.

CVSS2: 4.3
EPSS: Низкий
oracle-oval логотип

ELSA-2012-1090

около 14 лет назад

ELSA-2012-1090: nss and nspr security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
oracle-oval логотип

ELSA-2012-1091

около 14 лет назад

ELSA-2012-1091: nss, nspr, and nss-util security, bug fix, and enhancement update (MODERATE)

EPSS: Низкий
nvd логотип

CVE-2011-3671

около 14 лет назад

Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2011-3671

около 14 лет назад

Use-after-free vulnerability in the nsHTMLSelectElement function in ns ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2011-3671

около 14 лет назад

Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-3105

около 14 лет назад

The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a related issue to CVE-2011-3101.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2012-3105

около 14 лет назад

The glBufferData function in the WebGL implementation in Mozilla Firef ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2012-1947

около 14 лет назад

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2012-1952

The nsTableFrame::InsertFrames function in Mozilla Firefox 4.x through 13.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 13.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.11 does not properly perform a cast of a frame variable during processing of mixed row-group and column-group frames, which might allow remote attackers to execute arbitrary code via a crafted web site.

CVSS2: 6.8
4%
Низкий
около 14 лет назад
redhat логотип
CVE-2012-1964

The certificate-warning functionality in browser/components/certerror/content/aboutCertError.xhtml in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.6, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.6, and SeaMonkey before 2.10 does not properly handle attempted clickjacking of the about:certerror page, which allows man-in-the-middle attackers to trick users into adding an unintended exception via an IFRAME element.

CVSS2: 4.3
1%
Низкий
около 14 лет назад
oracle-oval логотип
ELSA-2012-1090

ELSA-2012-1090: nss and nspr security, bug fix, and enhancement update (MODERATE)

3%
Низкий
около 14 лет назад
oracle-oval логотип
ELSA-2012-1091

ELSA-2012-1091: nss, nspr, and nss-util security, bug fix, and enhancement update (MODERATE)

3%
Низкий
около 14 лет назад
nvd логотип
CVE-2011-3671

Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
debian логотип
CVE-2011-3671

Use-after-free vulnerability in the nsHTMLSelectElement function in ns ...

CVSS2: 7.5
2%
Низкий
около 14 лет назад
ubuntu логотип
CVE-2011-3671

Use-after-free vulnerability in the nsHTMLSelectElement function in nsHTMLSelectElement.cpp in Mozilla Firefox 4.x through 8.0, Thunderbird 5.0 through 8.0, and SeaMonkey before 2.6 allows remote attackers to execute arbitrary code via vectors involving removal of the parent node of an element.

CVSS2: 7.5
2%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-3105

The glBufferData function in the WebGL implementation in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 does not properly mitigate an unspecified flaw in an NVIDIA driver, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors, a related issue to CVE-2011-3101.

CVSS2: 9.3
4%
Низкий
около 14 лет назад
debian логотип
CVE-2012-3105

The glBufferData function in the WebGL implementation in Mozilla Firef ...

CVSS2: 9.3
4%
Низкий
около 14 лет назад
nvd логотип
CVE-2012-1947

Heap-based buffer overflow in the utf16_to_isolatin1 function in Mozilla Firefox 4.x through 12.0, Firefox ESR 10.x before 10.0.5, Thunderbird 5.0 through 12.0, Thunderbird ESR 10.x before 10.0.5, and SeaMonkey before 2.10 allows remote attackers to execute arbitrary code via vectors that trigger a character-set conversion failure.

CVSS2: 9.3
5%
Низкий
около 14 лет назад

Уязвимостей на страницу


Поделиться