Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

nvd логотип

CVE-2006-2784

больше 19 лет назад

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2006-2782

больше 19 лет назад

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2006-2779

больше 19 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2006-2783

больше 19 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2784

больше 19 лет назад

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows ...

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2006-2783

больше 19 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte- ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2782

больше 19 лет назад

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1 ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2785

больше 19 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5 ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2780

больше 19 лет назад

Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 all ...

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2006-2779

больше 19 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers ...

CVSS2: 9.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-2784

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.

CVSS2: 5.1
4%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2782

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1729, which allows remote attackers to read arbitrary files by inserting the target filename into a text box, then turning that box into a file upload control.

CVSS2: 4.3
1%
Низкий
больше 19 лет назад
nvd логотип
CVE-2006-2779

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.

CVSS2: 9.3
23%
Средний
больше 19 лет назад
nvd логотип
CVE-2006-2783

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

CVSS2: 4.3
5%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2784

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows ...

CVSS2: 5.1
4%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2783

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte- ...

CVSS2: 4.3
5%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2782

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1 ...

CVSS2: 4.3
1%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2785

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5 ...

CVSS2: 4.3
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2006-2780

Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 all ...

CVSS2: 9.3
27%
Средний
больше 19 лет назад
debian логотип
CVE-2006-2779

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers ...

CVSS2: 9.3
23%
Средний
больше 19 лет назад

Уязвимостей на страницу


Поделиться