Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

ubuntu логотип

CVE-2006-5633

около 19 лет назад

Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2006-5160

около 19 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that "I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not.

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2006-5159

около 19 лет назад

Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this issue, in which the researcher states that "we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this... I have not succeeded in making this code do anything more than cause a crash and eat up system resources"

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2006-5160

около 19 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox have unspecifi ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2006-4568

около 19 лет назад

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-4569

около 19 лет назад

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-4569

около 19 лет назад

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked ...

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2006-4568

около 19 лет назад

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remot ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-4569

около 19 лет назад

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2006-4568

около 19 лет назад

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2006-5633

Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference.

CVSS2: 5
16%
Средний
около 19 лет назад
nvd логотип
CVE-2006-5160

Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that "I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not.

CVSS3: 8.1
0%
Низкий
около 19 лет назад
nvd логотип
CVE-2006-5159

Stack-based buffer overflow in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving JavaScript. NOTE: the vendor and original researchers have released a follow-up comment disputing the severity of this issue, in which the researcher states that "we mentioned that there was a previously known Firefox vulnerability that could result in a stack overflow ending up in remote code execution. However, the code we presented did not in fact do this... I have not succeeded in making this code do anything more than cause a crash and eat up system resources"

CVSS2: 7.5
7%
Низкий
около 19 лет назад
debian логотип
CVE-2006-5160

Multiple unspecified vulnerabilities in Mozilla Firefox have unspecifi ...

CVSS3: 8.1
0%
Низкий
около 19 лет назад
nvd логотип
CVE-2006-4568

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

CVSS2: 4.3
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2006-4569

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.

CVSS2: 2.6
3%
Низкий
около 19 лет назад
debian логотип
CVE-2006-4569

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked ...

CVSS2: 2.6
3%
Низкий
около 19 лет назад
debian логотип
CVE-2006-4568

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remot ...

CVSS2: 4.3
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-4569

The popup blocker in Mozilla Firefox before 1.5.0.7 opens the "blocked popups" display in the context of the Location bar instead of the subframe from which the popup originated, which might make it easier for remote user-assisted attackers to conduct cross-site scripting (XSS) attacks.

CVSS2: 2.6
3%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2006-4568

Mozilla Firefox before 1.5.0.7 and SeaMonkey before 1.0.5 allows remote attackers to bypass the security model and inject content into the sub-frame of another site via targetWindow.frames[n].document.open(), which facilitates spoofing and other attacks.

CVSS2: 4.3
1%
Низкий
около 19 лет назад

Уязвимостей на страницу


Поделиться