Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314420232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 151

debian логотип

CVE-2005-0231

больше 20 лет назад

Firefox 1.0 does not invoke the Javascript Security Manager when a use ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0231

больше 20 лет назад

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2005-0232

больше 20 лет назад

Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."

EPSS: Низкий
redhat логотип

CVE-2005-0231

больше 20 лет назад

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

EPSS: Низкий
redhat логотип

CVE-2005-0233

больше 20 лет назад

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

EPSS: Низкий
nvd логотип

CVE-2005-0145

почти 21 год назад

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-0145

почти 21 год назад

Firefox before 1.0 does not properly distinguish between user-generate ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0145

почти 21 год назад

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2005-0143

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

EPSS: Низкий
redhat логотип

CVE-2005-0142

почти 21 год назад

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2005-0231

Firefox 1.0 does not invoke the Javascript Security Manager when a use ...

CVSS2: 2.6
3%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-0231

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

CVSS2: 2.6
3%
Низкий
больше 20 лет назад
redhat логотип
CVE-2005-0232

Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."

1%
Низкий
больше 20 лет назад
redhat логотип
CVE-2005-0231

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

3%
Низкий
больше 20 лет назад
redhat логотип
CVE-2005-0233

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

9%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-0145

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
debian логотип
CVE-2005-0145

Firefox before 1.0 does not properly distinguish between user-generate ...

CVSS2: 2.6
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0145

Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
redhat логотип
CVE-2005-0143

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

1%
Низкий
почти 21 год назад
redhat логотип
CVE-2005-0142

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

0%
Низкий
почти 21 год назад

Уязвимостей на страницу


Поделиться