Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2005-0590

почти 21 год назад

The installation confirmation dialog in Firefox before 1.0.1, Thunderb ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-1153

почти 21 год назад

Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a p ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-1159

почти 21 год назад

The native implementations of InstallTrigger and other functions in Fi ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-1157

почти 21 год назад

Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 all ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-0146

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2005-0230

почти 21 год назад

Firefox 1.0 does not prevent the user from dragging an executable file ...

CVSS2: 5.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0142

почти 21 год назад

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

CVSS2: 2.1
EPSS: Низкий
ubuntu логотип

CVE-2005-0144

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-1159

почти 21 год назад

The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-1155

почти 21 год назад

The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."

CVSS2: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2005-0590

The installation confirmation dialog in Firefox before 1.0.1, Thunderb ...

CVSS2: 5
2%
Низкий
почти 21 год назад
debian логотип
CVE-2005-1153

Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a p ...

CVSS2: 7.5
7%
Низкий
почти 21 год назад
debian логотип
CVE-2005-1159

The native implementations of InstallTrigger and other functions in Fi ...

CVSS2: 7.5
4%
Низкий
почти 21 год назад
debian логотип
CVE-2005-1157

Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 all ...

CVSS2: 7.5
9%
Низкий
почти 21 год назад
debian логотип
CVE-2005-0146

Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to ...

CVSS2: 5
1%
Низкий
почти 21 год назад
debian логотип
CVE-2005-0230

Firefox 1.0 does not prevent the user from dragging an executable file ...

CVSS2: 5.1
2%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0142

Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.

CVSS2: 2.1
0%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0144

Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-1159

The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.

CVSS2: 7.5
4%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-1155

The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."

CVSS2: 7.5
36%
Средний
почти 21 год назад

Уязвимостей на страницу


Поделиться