Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

debian логотип

CVE-2012-0473

больше 14 лет назад

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-0472

больше 14 лет назад

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2012-0472

больше 14 лет назад

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, F ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2012-0471

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2012-0471

больше 14 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x throug ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2012-0470

больше 14 лет назад

Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly execute arbitrary code by leveraging the use of "different number systems."

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2012-0470

больше 14 лет назад

Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::Light ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2012-0469

больше 14 лет назад

Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to execute arbitrary code via vectors related to crafted IndexedDB data.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2012-0469

больше 14 лет назад

Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRan ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2012-0468

больше 14 лет назад

The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (assertion failure and memory corruption) or possibly execute arbitrary code via vectors related to jsval.h and the js::array_shift function.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-0473

The WebGLBuffer::FindMaxUshortElement function in Mozilla Firefox 4.x ...

CVSS2: 5
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0472

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9, when certain Windows Vista and Windows 7 configurations are used, does not properly restrict font-rendering attempts, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 9.3
4%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0472

The cairo-dwrite implementation in Mozilla Firefox 4.x through 11.0, F ...

CVSS2: 9.3
4%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0471

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to inject arbitrary web script or HTML via a multibyte character set.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0471

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x throug ...

CVSS2: 4.3
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0470

Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::LightPixel function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (invalid gfxImageSurface free operation) or possibly execute arbitrary code by leveraging the use of "different number systems."

CVSS2: 10
10%
Средний
больше 14 лет назад
debian логотип
CVE-2012-0470

Heap-based buffer overflow in the nsSVGFEDiffuseLightingElement::Light ...

CVSS2: 10
10%
Средний
больше 14 лет назад
nvd логотип
CVE-2012-0469

Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRange::cycleCollection::Trace function in Mozilla Firefox 4.x through 11.0, Firefox ESR 10.x before 10.0.4, Thunderbird 5.0 through 11.0, Thunderbird ESR 10.x before 10.0.4, and SeaMonkey before 2.9 allows remote attackers to execute arbitrary code via vectors related to crafted IndexedDB data.

CVSS2: 10
7%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0469

Use-after-free vulnerability in the mozilla::dom::indexedDB::IDBKeyRan ...

CVSS2: 10
7%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0468

The browser engine in Mozilla Firefox 4.x through 11.0, Thunderbird 5.0 through 11.0, and SeaMonkey before 2.9 allows remote attackers to cause a denial of service (assertion failure and memory corruption) or possibly execute arbitrary code via vectors related to jsval.h and the js::array_shift function.

CVSS2: 10
4%
Низкий
больше 14 лет назад

Уязвимостей на страницу


Поделиться