Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

nvd логотип

CVE-2012-0460

больше 14 лет назад

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2012-0460

больше 14 лет назад

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thun ...

CVSS2: 6.4
EPSS: Низкий
nvd логотип

CVE-2012-0459

больше 14 лет назад

The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via dynamic modification of a keyframe followed by access to the cssText of the keyframe.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2012-0459

больше 14 лет назад

The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2012-0458

больше 14 лет назад

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2012-0458

больше 14 лет назад

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x b ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-0457

больше 14 лет назад

Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to execute arbitrary code via an SVG animation.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2012-0457

больше 14 лет назад

Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetwee ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2012-0456

больше 14 лет назад

The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to obtain sensitive information from process memory via vectors that trigger an out-of-bounds read.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-0456

больше 14 лет назад

The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4. ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2012-0460

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict write access to the window.fullScreen object, which allows remote attackers to spoof the user interface via a crafted web page.

CVSS2: 6.4
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0460

Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thun ...

CVSS2: 6.4
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0459

The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via dynamic modification of a keyframe followed by access to the cssText of the keyframe.

CVSS2: 7.5
4%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0459

The Cascading Style Sheets (CSS) implementation in Mozilla Firefox 4.x ...

CVSS2: 7.5
4%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0458

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 do not properly restrict setting the home page through the dragging of a URL to the home button, which allows user-assisted remote attackers to execute arbitrary JavaScript code with chrome privileges via a javascript: URL that is later interpreted in the about:sessionrestore context.

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0458

Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x b ...

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0457

Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetweenTimeContainer function in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to execute arbitrary code via an SVG animation.

CVSS2: 9.3
7%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0457

Use-after-free vulnerability in the nsSMILTimeValueSpec::ConvertBetwee ...

CVSS2: 9.3
7%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0456

The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird before 3.1.20 and 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 might allow remote attackers to obtain sensitive information from process memory via vectors that trigger an out-of-bounds read.

CVSS2: 5
3%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0456

The SVG Filters implementation in Mozilla Firefox before 3.6.28 and 4. ...

CVSS2: 5
3%
Низкий
больше 14 лет назад

Уязвимостей на страницу


Поделиться