Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2005-2429

больше 20 лет назад

Firefox, when opening Microsoft Word documents, does not properly set ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2395

больше 20 лет назад

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-2395

больше 20 лет назад

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2005-2395

больше 20 лет назад

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2005-3089

больше 20 лет назад

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.

EPSS: Низкий
nvd логотип

CVE-2005-2266

больше 20 лет назад

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-2270

больше 20 лет назад

Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-2269

больше 20 лет назад

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2264

больше 20 лет назад

Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-2263

больше 20 лет назад

The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2005-2429

Firefox, when opening Microsoft Word documents, does not properly set ...

CVSS2: 5
0%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
1%
Низкий
больше 20 лет назад
debian логотип
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the ...

CVSS2: 5
1%
Низкий
больше 20 лет назад
ubuntu логотип
CVE-2005-2395

Mozilla Firefox 1.0.4 and 1.0.5 does not choose the challenge with the strongest authentication scheme available as required by RFC2617, which might cause credentials to be sent in plaintext even if an encrypted channel is available.

CVSS2: 5
1%
Низкий
больше 20 лет назад
redhat логотип
CVE-2005-3089

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.

1%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2266

Firefox before 1.0.5 and Mozilla before 1.7.9 allows a child frame to call top.focus and other methods in a parent frame, even when the parent is in a different domain, which violates the same origin policy and allows remote attackers to steal sensitive information such as cookies and passwords from web sites whose child frames do not verify that they are in the same domain as their parents.

CVSS2: 5
2%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2270

Firefox before 1.0.5 and Mozilla before 1.7.9 does not properly clone base objects, which allows remote attackers to execute arbitrary code by navigating the prototype chain to reach a privileged object.

CVSS2: 7.5
29%
Средний
больше 20 лет назад
nvd логотип
CVE-2005-2269

Firefox before 1.0.5, Mozilla before 1.7.9, and Netscape 8.0.2 does not properly verify the associated types of DOM node names within the context of their namespaces, which allows remote attackers to modify certain tag properties, possibly leading to execution of arbitrary script or code, as demonstrated using an XHTML document with IMG tags with custom properties ("XHTML node spoofing").

CVSS2: 7.5
8%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2264

Firefox before 1.0.5 allows remote attackers to steal sensitive information by opening a malicious link in the Firefox sidebar using the _search target, then injecting script into other pages via a data: URL.

CVSS2: 7.5
3%
Низкий
больше 20 лет назад
nvd логотип
CVE-2005-2263

The InstallTrigger.install method in Firefox before 1.0.5 and Mozilla before 1.7.9 allows remote attackers to execute a callback function in the context of another domain by forcing a page navigation after the install method has been called, which causes the callback to be run in the context of the new page and results in a same origin violation.

CVSS2: 5
5%
Низкий
больше 20 лет назад

Уязвимостей на страницу


Поделиться