Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014120232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 14 782

debian логотип

CVE-2004-1381

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background ...

CVSS2: 5
EPSS: Средний
debian логотип

CVE-2004-1380

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (backgroun ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2004-1381

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.

CVSS2: 5
EPSS: Средний
nvd логотип

CVE-2004-0866

почти 21 год назад

Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0905

почти 21 год назад

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.

CVSS2: 4.6
EPSS: Низкий
debian логотип

CVE-2004-0905

почти 21 год назад

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and ...

CVSS2: 4.6
EPSS: Низкий
redhat логотип

CVE-2004-0904

почти 21 год назад

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.

EPSS: Средний
nvd логотип

CVE-2004-0779

почти 21 год назад

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2004-0757

почти 21 год назад

Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2004-0762

почти 21 год назад

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2004-1381

Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background ...

CVSS2: 5
13%
Средний
почти 21 год назад
debian логотип
CVE-2004-1380

Firefox before 1.0 and Mozilla before 1.7.5 allows inactive (backgroun ...

CVSS2: 5
14%
Средний
почти 21 год назад
ubuntu логотип
CVE-2004-1381

Firefox before 1.0 and Mozilla before 1.7.5 allow inactive (background) tabs to focus on input being entered in the active tab, as originally reported using form fields, which allows remote attackers to steal sensitive data that is intended for other sites, which could facilitate phishing attacks.

CVSS2: 5
13%
Средний
почти 21 год назад
nvd логотип
CVE-2004-0866

Internet Explorer 6.0 allows web sites to set cookies for country-specific top-level domains, such as .ltd.uk, .plc.uk, and .sch.uk, which could allow remote attackers to perform a session fixation attack and hijack a user's HTTP session.

CVSS2: 7.5
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2004-0905

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows remote attackers to perform cross-domain scripting and possibly execute arbitrary code by convincing a user to drag and drop javascript: links to a frame or page in another domain.

CVSS2: 4.6
6%
Низкий
почти 21 год назад
debian логотип
CVE-2004-0905

Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and ...

CVSS2: 4.6
6%
Низкий
почти 21 год назад
redhat логотип
CVE-2004-0904

Integer overflow in the bitmap (BMP) decoder for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to execute arbitrary code via wide bitmap files that trigger heap-based buffer overflows.

21%
Средний
почти 21 год назад
nvd логотип
CVE-2004-0779

The (1) Mozilla 1.6, (2) Firebird 0.7 and (3) Firefox 0.8 web browsers do not properly verify that cached passwords for SSL encrypted sites are only sent via SSL encrypted sessions to the site, which allows a remote attacker to cause a cached password to be sent in cleartext to a spoofed site.

CVSS2: 7.5
1%
Низкий
почти 21 год назад
nvd логотип
CVE-2004-0757

Heap-based buffer overflow in the SendUidl in the POP3 capability for Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, may allow remote POP3 mail servers to execute arbitrary code.

CVSS2: 10
4%
Низкий
почти 21 год назад
nvd логотип
CVE-2004-0762

Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.

CVSS2: 5
1%
Низкий
почти 21 год назад

Уязвимостей на страницу


Поделиться