Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

debian логотип

CVE-2006-0293

почти 20 лет назад

The function allocation code (js_NewFunction in jsfun.c) in Firefox 1. ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2006-0294

почти 20 лет назад

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2006-0292

почти 20 лет назад

The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before ...

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2006-0296

почти 20 лет назад

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, a ...

CVSS2: 5
EPSS: Средний
ubuntu логотип

CVE-2006-0293

почти 20 лет назад

The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-0295

почти 20 лет назад

Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.

CVSS2: 5.1
EPSS: Высокий
ubuntu логотип

CVE-2006-0294

почти 20 лет назад

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2006-0292

почти 20 лет назад

The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2006-0296

почти 20 лет назад

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

CVSS2: 5
EPSS: Средний
redhat логотип

CVE-2006-0296

почти 20 лет назад

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2006-0293

The function allocation code (js_NewFunction in jsfun.c) in Firefox 1. ...

CVSS2: 7.5
4%
Низкий
почти 20 лет назад
debian логотип
CVE-2006-0294

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript ...

CVSS2: 7.5
8%
Низкий
почти 20 лет назад
debian логотип
CVE-2006-0292

The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before ...

CVSS2: 7.5
10%
Средний
почти 20 лет назад
debian логотип
CVE-2006-0296

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, a ...

CVSS2: 5
41%
Средний
почти 20 лет назад
ubuntu логотип
CVE-2006-0293

The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.

CVSS2: 7.5
4%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2006-0295

Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.

CVSS2: 5.1
82%
Высокий
почти 20 лет назад
ubuntu логотип
CVE-2006-0294

Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.

CVSS2: 7.5
8%
Низкий
почти 20 лет назад
ubuntu логотип
CVE-2006-0292

The Javascript interpreter (jsinterp.c) in Mozilla and Firefox before 1.5.1 does not properly dereference objects, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via unknown attack vectors related to garbage collection.

CVSS2: 7.5
10%
Средний
почти 20 лет назад
ubuntu логотип
CVE-2006-0296

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

CVSS2: 5
41%
Средний
почти 20 лет назад
redhat логотип
CVE-2006-0296

The XULDocument.persist function in Mozilla, Firefox before 1.5.0.1, and SeaMonkey before 1.0 does not validate the attribute name, which allows remote attackers to execute arbitrary Javascript by injecting RDF data into the user's localstore.rdf file.

41%
Средний
почти 20 лет назад

Уязвимостей на страницу


Поделиться