Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

nvd логотип

CVE-2011-2990

почти 15 лет назад

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-2990

почти 15 лет назад

The implementation of Content Security Policy (CSP) violation reports ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-2989

почти 15 лет назад

The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products does not properly implement WebGL, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2989

почти 15 лет назад

The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x bef ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-2988

почти 15 лет назад

Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2988

почти 15 лет назад

Buffer overflow in an unspecified string class in the WebGL shader imp ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-2987

почти 15 лет назад

Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANGLE), as used in the WebGL implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products might allow remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2987

почти 15 лет назад

Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANG ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-2986

почти 15 лет назад

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-2986

почти 15 лет назад

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x bef ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2011-2990

The implementation of Content Security Policy (CSP) violation reports in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, and possibly other products does not remove proxy-authorization credentials from the listed request headers, which allows attackers to obtain sensitive information by reading a report, related to incorrect host resolution that occurs with certain redirects.

CVSS2: 5
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2990

The implementation of Content Security Policy (CSP) violation reports ...

CVSS2: 5
1%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2989

The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x before 2.3, Thunderbird before 6, and possibly other products does not properly implement WebGL, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.

CVSS2: 10
5%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2989

The browser engine in Mozilla Firefox 4.x through 5, SeaMonkey 2.x bef ...

CVSS2: 10
5%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2988

Buffer overflow in an unspecified string class in the WebGL shader implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long source-code block for a shader.

CVSS2: 10
5%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2988

Buffer overflow in an unspecified string class in the WebGL shader imp ...

CVSS2: 10
5%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2987

Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANGLE), as used in the WebGL implementation in Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products might allow remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
5%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2987

Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANG ...

CVSS2: 10
5%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2986

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x before 2.3, and possibly other products, when the Direct2D (aka D2D) API is used on Windows, allows remote attackers to bypass the Same Origin Policy, and obtain sensitive image data from a different domain, by inserting this data into a canvas.

CVSS2: 5
1%
Низкий
почти 15 лет назад
debian логотип
CVE-2011-2986

Mozilla Firefox 4.x through 5, Thunderbird before 6, SeaMonkey 2.x bef ...

CVSS2: 5
1%
Низкий
почти 15 лет назад

Уязвимостей на страницу


Поделиться