Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 14 793

CVE-2004-1156
Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability.

CVE-2004-1753
The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs.

CVE-2004-2225
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.

CVE-2004-2227
Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions.

CVE-2004-2228
Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.

CVE-2004-2657
Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision.
CVE-2004-2225
Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitr ...
CVE-2004-2228
Mozilla Firefox before 1.0 is installed with world-writable permission ...
CVE-2004-1200
Firefox and Mozilla allow remote attackers to cause a denial of servic ...
CVE-2004-0904
Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox befor ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
![]() | CVE-2004-1156 Mozilla before 1.7.6, and Firefox before 1.0.1, allows remote attackers to spoof arbitrary web sites by injecting content from one window into a target window whose name is known but resides in a different domain, as demonstrated using a pop-up window on a trusted web site, aka the "window injection" vulnerability. | CVSS2: 4.3 | 1% Низкий | больше 20 лет назад |
![]() | CVE-2004-1753 The Apple Java plugin, as used in Netscape 7.1 and 7.2, Mozilla 1.7.2, and Firefox 0.9.3 on MacOS X 10.3.5, when tabbed browsing is enabled, does not properly handle SetWindow(NULL) calls, which allows Java applets from one tab to draw to other tabs and facilitates phishing attacks that spoof tabs. | CVSS2: 2.6 | 1% Низкий | больше 20 лет назад |
![]() | CVE-2004-2225 Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button. | CVSS2: 5 | 1% Низкий | больше 20 лет назад |
![]() | CVE-2004-2227 Mozilla Firefox before 1.0 truncates long filenames in the file download dialog box, which makes it easier for remote attackers to trick users into downloading files with dangerous extensions. | CVSS2: 5 | 1% Низкий | больше 20 лет назад |
![]() | CVE-2004-2228 Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges. | CVSS2: 7.2 | 0% Низкий | больше 20 лет назад |
![]() | CVE-2004-2657 Mozilla Firefox 1.5.0.1, and possibly other versions, preserves some records of user activity even after uninstalling, which allows local users who share a Windows profile to view the records after a new installation of Firefox, as reported for the list of Passwords Never Saved web sites. NOTE: The vendor has disputed this issue, stating that "The uninstaller is primarily there to uninstall the application. It is not there to uninstall user data. For the moment I will stick by my module-owner decision. | CVSS2: 1.7 | 0% Низкий | больше 20 лет назад |
CVE-2004-2225 Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitr ... | CVSS2: 5 | 1% Низкий | больше 20 лет назад | |
CVE-2004-2228 Mozilla Firefox before 1.0 is installed with world-writable permission ... | CVSS2: 7.2 | 0% Низкий | больше 20 лет назад | |
CVE-2004-1200 Firefox and Mozilla allow remote attackers to cause a denial of servic ... | CVSS2: 5 | 1% Низкий | больше 20 лет назад | |
CVE-2004-0904 Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox befor ... | CVSS2: 10 | 32% Средний | больше 20 лет назад |
Уязвимостей на страницу