Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

debian логотип

CVE-2012-0452

больше 14 лет назад

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Th ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2012-0452

больше 14 лет назад

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2012-0452

больше 14 лет назад

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2012-0450

больше 14 лет назад

Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.

CVSS2: 2.1
EPSS: Низкий
debian логотип

CVE-2012-0450

больше 14 лет назад

Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and ...

CVSS2: 2.1
EPSS: Низкий
nvd логотип

CVE-2012-0449

больше 14 лет назад

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2012-0449

больше 14 лет назад

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2012-0447

больше 14 лет назад

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2012-0447

больше 14 лет назад

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaM ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2012-0446

больше 14 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Th ...

CVSS2: 7.5
3%
Низкий
больше 14 лет назад
ubuntu логотип
CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.

CVSS2: 7.5
3%
Низкий
больше 14 лет назад
redhat логотип
CVE-2012-0452

Use-after-free vulnerability in Mozilla Firefox 10.x before 10.0.1, Thunderbird 10.x before 10.0.1, and SeaMonkey 2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger failure of an nsXBLDocumentInfo::ReadPrototypeBindings function call, related to the cycle collector's access to a hash table containing a stale XBL binding.

CVSS2: 6.8
3%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0450

Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and Mac OS X set weak permissions for Firefox Recovery Key.html, which might allow local users to read a Firefox Sync key via standard filesystem operations.

CVSS2: 2.1
0%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0450

Mozilla Firefox 4.x through 9.0 and SeaMonkey before 2.7 on Linux and ...

CVSS2: 2.1
0%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0449

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before 3.1.18 and 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed XSLT stylesheet that is embedded in a document.

CVSS2: 9.3
6%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0449

Mozilla Firefox before 3.6.26 and 4.x through 9.0, Thunderbird before ...

CVSS2: 9.3
6%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0447

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 do not properly initialize data for image/vnd.microsoft.icon images, which allows remote attackers to obtain potentially sensitive information by reading a PNG image that was created through conversion from an ICO image.

CVSS2: 5
2%
Низкий
больше 14 лет назад
debian логотип
CVE-2012-0447

Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaM ...

CVSS2: 5
2%
Низкий
больше 14 лет назад
nvd логотип
CVE-2012-0446

Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox 4.x through 9.0, Thunderbird 5.0 through 9.0, and SeaMonkey before 2.7 allow remote attackers to inject arbitrary web script or HTML via a (1) web page or (2) Firefox extension, related to improper enforcement of XPConnect security restrictions for frame scripts that call untrusted objects.

CVSS2: 4.3
2%
Низкий
больше 14 лет назад

Уязвимостей на страницу


Поделиться