Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

debian логотип

CVE-2011-2362

около 15 лет назад

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonke ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2011-0085

около 15 лет назад

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-0085

около 15 лет назад

Use-after-free vulnerability in the nsXULCommandDispatcher function in ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2011-0083

около 15 лет назад

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-0083

около 15 лет назад

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem func ...

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-0083

около 15 лет назад

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-2367

около 15 лет назад

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.

CVSS2: 6.4
EPSS: Низкий
ubuntu логотип

CVE-2011-2373

около 15 лет назад

Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document.

CVSS2: 7.6
EPSS: Низкий
ubuntu логотип

CVE-2011-2362

около 15 лет назад

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that differ only in a trailing dot, which allows remote web servers to bypass the Same Origin Policy via Set-Cookie headers.

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2011-2374

около 15 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2011-2362

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonke ...

CVSS2: 5
2%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0085

Use-after-free vulnerability in the nsXULCommandDispatcher function in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to execute arbitrary code via a crafted XUL document that dequeues the current command updater.

CVSS2: 10
6%
Низкий
около 15 лет назад
debian логотип
CVE-2011-0085

Use-after-free vulnerability in the nsXULCommandDispatcher function in ...

CVSS2: 10
6%
Низкий
около 15 лет назад
nvd логотип
CVE-2011-0083

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

CVSS2: 10
6%
Низкий
около 15 лет назад
debian логотип
CVE-2011-0083

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem func ...

CVSS2: 10
6%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-0083

Use-after-free vulnerability in the nsSVGPathSegList::ReplaceItem function in the implementation of SVG element lists in Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a user-supplied callback.

CVSS2: 10
6%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-2367

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.

CVSS2: 6.4
2%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-2373

Use-after-free vulnerability in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14, when JavaScript is disabled, allows remote attackers to execute arbitrary code via a crafted XUL document.

CVSS2: 7.6
5%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-2362

Mozilla Firefox before 3.6.18, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 do not distinguish between cookies for two domain names that differ only in a trailing dot, which allows remote web servers to bypass the Same Origin Policy via Set-Cookie headers.

CVSS2: 5
2%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-2374

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, and Thunderbird before 3.1.11, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
5%
Низкий
около 15 лет назад

Уязвимостей на страницу


Поделиться