Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

debian логотип

CVE-2012-0479

больше 14 лет назад

Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thun ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0478

больше 14 лет назад

The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2012-0478

больше 14 лет назад

The texImage2D implementation in the WebGL subsystem in Mozilla Firefo ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2012-0477

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) ISO-2022-KR or (2) ISO-2022-CN character set.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0477

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0475

больше 14 лет назад

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2012-0475

больше 14 лет назад

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and Se ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2012-0474

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Universal XSS (UXSS)."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0474

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in the docshell implementatio ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0473

больше 14 лет назад

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-0479

Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thun ...

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0478

The texImage2D implementation in the WebGL subsystem in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 does not properly restrict JSVAL_TO_OBJECT casts, which might allow remote attackers to execute arbitrary code via a crafted web page.

CVSS2: 9.3
4%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0478

The texImage2D implementation in the WebGL subsystem in Mozilla Firefo ...

CVSS2: 9.3
4%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0477

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allow remote attackers to inject arbitrary web script or HTML via the (1) ISO-2022-KR or (2) ISO-2022-CN character set.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0477

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox ...

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0475

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 do not properly construct the Origin and Sec-WebSocket-Origin HTTP headers, which might allow remote attackers to bypass an IPv6 literal ACL via a cross-site (1) XMLHttpRequest or (2) WebSocket operation involving a nonstandard port number and an IPv6 address that contains certain zero fields.

CVSS2: 2.6
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0475

Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and Se ...

CVSS2: 2.6
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0474

Cross-site scripting (XSS) vulnerability in the docshell implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via vectors related to short-circuited page loads, aka "Universal XSS (UXSS)."

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0474

Cross-site scripting (XSS) vulnerability in the docshell implementatio ...

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0473

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 calls the FindMaxElementInSubArray function with incorrect template arguments, which allows remote attackers to obtain sensitive information from video memory via a crafted WebGL.drawElements call.

CVSS2: 5
2%
Низкий
больше 14 лет назад

Уязвимостей на страницу


Поделиться