Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

ubuntu логотип

CVE-2008-7293

почти 15 лет назад

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2011-2605

около 15 лет назад

CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-2605

около 15 лет назад

CRLF injection vulnerability in the nsCookieService::SetCookieStringIn ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2011-2377

около 15 лет назад

Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace image.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-2377

около 15 лет назад

Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird befor ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-2376

около 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and Thunderbird before 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2376

около 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-2375

около 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2375

около 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-2374

около 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2008-7293

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

CVSS2: 5.8
2%
Низкий
почти 15 лет назад
nvd логотип
CVE-2011-2605

CRLF injection vulnerability in the nsCookieService::SetCookieStringInternal function in netwerk/cookie/nsCookieService.cpp in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allows remote attackers to bypass intended access restrictions via a string containing a \n (newline) character, which is not properly handled in a JavaScript "document.cookie =" expression, a different vulnerability than CVE-2011-2374.

CVSS2: 4.3
1%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2605

CRLF injection vulnerability in the nsCookieService::SetCookieStringIn ...

CVSS2: 4.3
1%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-2377

Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace image.

CVSS2: 5
4%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2377

Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird befor ...

CVSS2: 5
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-2376

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and Thunderbird before 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
4%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2376

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
4%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-2375

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 5.0 and Thunderbird through 3.1.11 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
6%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2375

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 10
6%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-2374

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
5%
Низкий
около 15 лет назад

Уязвимостей на страницу


Поделиться