Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014120232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 14 782

debian логотип

CVE-2005-0588

больше 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:in ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-0146

больше 20 лет назад

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-0527

больше 20 лет назад

Firefox 1.0 allows remote attackers to execute arbitrary code via plug ...

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2005-0255

больше 20 лет назад

String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbi ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-0590

больше 20 лет назад

The installation confirmation dialog in Firefox before 1.0.1, Thunderb ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-0142

больше 20 лет назад

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozill ...

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2005-0144

больше 20 лет назад

Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lo ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-1159

больше 20 лет назад

The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0588

больше 20 лет назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-0142

больше 20 лет назад

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

CVSS2: 2.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2005-0588

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:in ...

CVSS2: 5
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-0146

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to ...

CVSS2: 5
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-0527

Firefox 1.0 allows remote attackers to execute arbitrary code via plug ...

CVSS2: 5.1
3%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-0255

String handling functions in Mozilla 1.7.3, Firefox 1.0, and Thunderbi ...

CVSS2: 5
8%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-0590

The installation confirmation dialog in Firefox before 1.0.1, Thunderb ...

CVSS2: 5
2%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-0142

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozill ...

CVSS2: 2.1
0%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-0144

Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lo ...

CVSS2: 2.6
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-1159

The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.

CVSS2: 7.5
4%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-0588

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-0142

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

CVSS2: 2.1
0%
Низкий
больше 20 лет назад

Уязвимостей на страницу


Поделиться