Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 304

debian логотип

CVE-2010-3774

больше 15 лет назад

The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-3773

больше 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-0179.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-3773

больше 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-3772

больше 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-3772

больше 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-3771

больше 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2010-3771

больше 15 лет назад

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2010-3770

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to angle brackets during rendering.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-3770

больше 15 лет назад

Multiple cross-site scripting (XSS) vulnerabilities in the rendering e ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-3769

больше 15 лет назад

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2010-3774

The NS_SecurityCompareURIs function in netwerk/base/public/nsNetUtil.h ...

CVSS2: 4.3
2%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3773

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-0179.

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3773

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 6.8
3%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3772

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly calculate index values for certain child content in a XUL tree, which allows remote attackers to execute arbitrary code via vectors involving a DIV element within a treechildren element.

CVSS2: 9.3
5%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3772

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 9.3
5%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3771

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, does not properly handle injection of an ISINDEX element into an about:blank page, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges via vectors related to redirection to a chrome: URI.

CVSS2: 6.8
2%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3771

Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey b ...

CVSS2: 6.8
2%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3770

Multiple cross-site scripting (XSS) vulnerabilities in the rendering engine in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allow remote attackers to inject arbitrary web script or HTML via (1) x-mac-arabic, (2) x-mac-farsi, or (3) x-mac-hebrew characters that may be converted to angle brackets during rendering.

CVSS2: 4.3
4%
Низкий
больше 15 лет назад
debian логотип
CVE-2010-3770

Multiple cross-site scripting (XSS) vulnerabilities in the rendering e ...

CVSS2: 4.3
4%
Низкий
больше 15 лет назад
nvd логотип
CVE-2010-3769

The line-breaking implementation in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, Thunderbird before 3.0.11 and 3.1.x before 3.1.7, and SeaMonkey before 2.0.11 on Windows does not properly handle long strings, which allows remote attackers to execute arbitrary code via a crafted document.write call that triggers a buffer over-read.

CVSS2: 9.3
5%
Низкий
больше 15 лет назад

Уязвимостей на страницу


Поделиться