Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

redhat логотип

CVE-2011-3647

почти 15 лет назад

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2011-2998

почти 15 лет назад

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2998

почти 15 лет назад

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-2998

почти 15 лет назад

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-3866

почти 15 лет назад

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-3866

почти 15 лет назад

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly re ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-3232

почти 15 лет назад

YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2011-3232

почти 15 лет назад

YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, a ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2011-3005

почти 15 лет назад

Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OGG headers in a .ogg file.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2011-3005

почти 15 лет назад

Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunder ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2011-3647

The JSSubScriptLoader in Mozilla Firefox before 3.6.24 and Thunderbird before 3.1.6 does not properly handle XPCNativeWrappers during calls to the loadSubScript method in an add-on, which makes it easier for remote attackers to gain privileges via a crafted web site that leverages certain unwrapping behavior, a related issue to CVE-2011-3004.

CVSS2: 6.8
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2998

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

CVSS2: 10
5%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2998

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote ...

CVSS2: 10
5%
Низкий
почти 15 лет назад
ubuntu логотип
CVE-2011-2998

Integer underflow in Mozilla Firefox 3.6.x before 3.6.23 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via JavaScript code containing a large RegExp expression.

CVSS2: 10
5%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3866

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly restrict availability of motion data events, which makes it easier for remote attackers to read keystrokes by leveraging JavaScript code running in a background tab.

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3866

Mozilla Firefox before 7.0 and SeaMonkey before 2.4 do not properly re ...

CVSS2: 4.3
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3232

YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, and SeaMonkey before 2.4, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted JavaScript.

CVSS2: 9.3
5%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3232

YARR, as used in Mozilla Firefox before 7.0, Thunderbird before 7.0, a ...

CVSS2: 9.3
5%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-3005

Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunderbird before 7.0, and SeaMonkey before 2.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted OGG headers in a .ogg file.

CVSS2: 9.3
4%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-3005

Use-after-free vulnerability in Mozilla Firefox 4.x through 6, Thunder ...

CVSS2: 9.3
4%
Низкий
почти 15 лет назад

Уязвимостей на страницу


Поделиться