Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 299

debian логотип

CVE-2010-2770

почти 16 лет назад

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2769

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2769

почти 16 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2768

почти 16 лет назад

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2768

почти 16 лет назад

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2767

почти 16 лет назад

The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability."

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-2767

почти 16 лет назад

The navigator.plugins implementation in Mozilla Firefox before 3.5.12 ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2766

почти 16 лет назад

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-2766

почти 16 лет назад

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3. ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2765

почти 16 лет назад

Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2010-2770

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 9.3
4%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-2769

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

CVSS2: 4.3
2%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-2769

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5 ...

CVSS2: 4.3
2%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-2768

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.

CVSS2: 4.3
2%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-2768

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 4.3
2%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-2767

The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability."

CVSS2: 9.3
5%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-2767

The navigator.plugins implementation in Mozilla Firefox before 3.5.12 ...

CVSS2: 9.3
5%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-2766

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle the removal of DOM nodes during normalization, which might allow remote attackers to execute arbitrary code via vectors involving access to a deleted object.

CVSS2: 9.3
5%
Низкий
почти 16 лет назад
debian логотип
CVE-2010-2766

The normalizeDocument function in Mozilla Firefox before 3.5.12 and 3. ...

CVSS2: 9.3
5%
Низкий
почти 16 лет назад
nvd логотип
CVE-2010-2765

Integer overflow in the FRAMESET element implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a large number of values in the cols (aka columns) attribute, leading to a heap-based buffer overflow.

CVSS2: 9.3
6%
Низкий
почти 16 лет назад

Уязвимостей на страницу


Поделиться