Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 691

ubuntu логотип

CVE-2011-2984

около 15 лет назад

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2011-2981

около 15 лет назад

The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2011-0084

около 15 лет назад

The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-0084

около 15 лет назад

The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox be ...

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2983

около 15 лет назад

Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2011-2990

около 15 лет назад

The implementation of Content Security Policy (CSP) violation reports ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2011-2988

около 15 лет назад

Buffer overflow in an unspecified string class in the WebGL shader imp ...

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2993

около 15 лет назад

The implementation of digital signatures for JAR files in Mozilla Fire ...

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2011-2987

около 15 лет назад

Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANG ...

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2011-2992

около 15 лет назад

The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2011-2984

Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly handle the dropping of a tab element, which allows remote attackers to execute arbitrary JavaScript code with chrome privileges by establishing a content area and registering for drop events.

CVSS2: 10
4%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-2981

The event-management implementation in Mozilla Firefox before 3.6.20, SeaMonkey 2.x, Thunderbird 3.x before 3.1.12, and possibly other products does not properly select the context for script to run in, which allows remote attackers to bypass the Same Origin Policy or execute arbitrary JavaScript code with chrome privileges via a crafted web site.

CVSS2: 9.3
2%
Низкий
около 15 лет назад
ubuntu логотип
CVE-2011-0084

The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox before 3.6.20, and 4.x through 5; Thunderbird 3.x before 3.1.12 and other versions before 6; SeaMonkey 2.x before 2.3; and possibly other products does not properly handle SVG text, which allows remote attackers to execute arbitrary code via unspecified vectors that lead to a "dangling pointer."

CVSS2: 10
5%
Низкий
около 15 лет назад
debian логотип
CVE-2011-0084

The SVGTextElement.getCharNumAtPosition function in Mozilla Firefox be ...

CVSS2: 10
5%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2983

Mozilla Firefox before 3.6.20, Thunderbird 2.x and 3.x before 3.1.12, ...

CVSS2: 4.3
2%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2990

The implementation of Content Security Policy (CSP) violation reports ...

CVSS2: 5
1%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2988

Buffer overflow in an unspecified string class in the WebGL shader imp ...

CVSS2: 10
5%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2993

The implementation of digital signatures for JAR files in Mozilla Fire ...

CVSS2: 9.3
1%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2987

Heap-based buffer overflow in Almost Native Graphics Layer Engine (ANG ...

CVSS2: 10
5%
Низкий
около 15 лет назад
debian логотип
CVE-2011-2992

The Ogg reader in the browser engine in Mozilla Firefox 4.x through 5, ...

CVSS2: 10
4%
Низкий
около 15 лет назад

Уязвимостей на страницу


Поделиться