Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 425

nvd логотип

CVE-2005-2602

больше 20 лет назад

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-2602

больше 20 лет назад

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to o ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-2602

больше 20 лет назад

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-2429

больше 20 лет назад

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2429

больше 20 лет назад

Firefox, when opening Microsoft Word documents, does not properly set ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2395

больше 20 лет назад

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2395

больше 20 лет назад

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2395

больше 20 лет назад

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2005-3089

больше 20 лет назад

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.

EPSS: Низкий
nvd логотип

CVE-2005-2269

больше 20 лет назад

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2005-2602

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
0%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-2602

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to o ...

CVSS2: 2.6
0%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2602

Mozilla Thunderbird 1.0 and Firefox 1.0.6 allows remote attackers to obfuscate URIs via a long URI, which causes the address bar to go blank and could facilitate phishing attacks.

CVSS2: 2.6
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2429

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

CVSS2: 5
0%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-2429

Firefox, when opening Microsoft Word documents, does not properly set ...

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the ...

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
1%
Низкий
больше 20 лет назад
redhat логотип
CVE-2005-3089

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.

1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2269

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

CVSS2: 7.5
8%
Низкий
больше 20 лет назад

Уязвимостей на страницу


Поделиться