Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 151
CVE-2006-2784
The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.
CVE-2006-2782
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.
CVE-2006-2779
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.
CVE-2006-2783
Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.
CVE-2006-2784
The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows ...
CVE-2006-2783
Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte- ...
CVE-2006-2782
Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1 ...
CVE-2006-2785
Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5 ...
CVE-2006-2780
Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 all ...
CVE-2006-2779
Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2006-2784 The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site. | CVSS2: 5.1 | 4% Низкий | больше 19 лет назад | |
CVE-2006-2782 Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control. | CVSS2: 4.3 | 1% Низкий | больше 19 лет назад | |
CVE-2006-2779 Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption. | CVSS2: 9.3 | 23% Средний | больше 19 лет назад | |
CVE-2006-2783 Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT. | CVSS2: 4.3 | 5% Низкий | больше 19 лет назад | |
CVE-2006-2784 The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows ... | CVSS2: 5.1 | 4% Низкий | больше 19 лет назад | |
CVE-2006-2783 Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte- ... | CVSS2: 4.3 | 5% Низкий | больше 19 лет назад | |
CVE-2006-2782 Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1 ... | CVSS2: 4.3 | 1% Низкий | больше 19 лет назад | |
CVE-2006-2785 Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5 ... | CVSS2: 4.3 | 2% Низкий | больше 19 лет назад | |
CVE-2006-2780 Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 all ... | CVSS2: 9.3 | 27% Средний | больше 19 лет назад | |
CVE-2006-2779 Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers ... | CVSS2: 9.3 | 23% Средний | больше 19 лет назад |
Уязвимостей на страницу