Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

debian логотип

CVE-2011-3650

почти 15 лет назад

Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird befo ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-3649

почти 15 лет назад

Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2011-3649

почти 15 лет назад

Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) A ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2011-3648

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-3648

почти 15 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-3647

почти 15 лет назад

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2011-3647

почти 15 лет назад

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird ...

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2011-3653

почти 15 лет назад

Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-3654

почти 15 лет назад

The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-3651

почти 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-3650

Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird befo ...

CVSS2: 9.3
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3649

Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) API is used on Windows in conjunction with the Azure graphics back-end, allow remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas. NOTE: this issue exists because of a CVE-2011-2986 regression.

CVSS2: 2.6
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3649

Mozilla Firefox 7.0 and Thunderbird 7.0, when the Direct2D (aka D2D) A ...

CVSS2: 2.6
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3648

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 allows remote attackers to inject arbitrary web script or HTML via crafted text with Shift JIS encoding.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3648

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6 ...

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3647

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.

CVSS2: 9.3
2%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3647

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird ...

CVSS2: 9.3
2%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-3653

Mozilla Firefox before 8.0 and Thunderbird before 8.0 on Mac OS X do not properly interact with the GPU memory behavior of a certain driver for Intel integrated GPUs, which allows remote attackers to bypass the Same Origin Policy and read image data via vectors related to WebGL textures.

CVSS2: 5
1%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-3654

The browser engine in Mozilla Firefox before 8.0 and Thunderbird before 8.0 does not properly handle links from SVG mpath elements to non-SVG elements, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 10
4%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-3651

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 7.0 and Thunderbird 7.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
6%
Низкий
почти 15 лет назад

Уязвимостей на страницу


Поделиться