Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 299

nvd логотип

CVE-2010-1209

около 16 лет назад

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-1209

около 16 лет назад

Use-after-free vulnerability in the NodeIterator implementation in Moz ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-1208

около 16 лет назад

Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2010-1208

около 16 лет назад

Use-after-free vulnerability in the attribute-cloning functionality in ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2010-1207

около 16 лет назад

Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-1207

около 16 лет назад

Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not prope ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2010-1214

около 16 лет назад

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2010-1209

около 16 лет назад

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2010-1208

около 16 лет назад

Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2010-1210

около 16 лет назад

intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-1209

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.

CVSS2: 9.3
5%
Низкий
около 16 лет назад
debian логотип
CVE-2010-1209

Use-after-free vulnerability in the NodeIterator implementation in Moz ...

CVSS2: 9.3
5%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-1208

Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.

CVSS3: 8.8
5%
Низкий
около 16 лет назад
debian логотип
CVE-2010-1208

Use-after-free vulnerability in the attribute-cloning functionality in ...

CVSS3: 8.8
5%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-1207

Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.

CVSS2: 4.3
1%
Низкий
около 16 лет назад
debian логотип
CVE-2010-1207

Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not prope ...

CVSS2: 4.3
1%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2010-1214

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via plugin content with many parameter elements.

CVSS2: 9.3
8%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2010-1209

Use-after-free vulnerability in the NodeIterator implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via a crafted NodeFilter that detaches DOM nodes, related to the NodeIterator interface and a javascript callback.

CVSS2: 9.3
5%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2010-1208

Use-after-free vulnerability in the attribute-cloning functionality in the DOM implementation in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remote attackers to execute arbitrary code via vectors related to deletion of an event attribute node with a nonzero reference count.

CVSS3: 8.8
5%
Низкий
около 16 лет назад
ubuntu логотип
CVE-2010-1210

intl/uconv/util/nsUnicodeDecodeHelper.cpp in Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 inserts a U+FFFD sequence into text in certain circumstances involving undefined positions, which might make it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted 8-bit text.

CVSS2: 4.3
1%
Низкий
около 16 лет назад

Уязвимостей на страницу


Поделиться