Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2005-0590
The installation confirmation dialog in Firefox before 1.0.1, Thunderb ...
CVE-2005-1153
Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a p ...
CVE-2005-1159
The native implementations of InstallTrigger and other functions in Fi ...
CVE-2005-1157
Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 all ...
CVE-2005-0146
Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to ...
CVE-2005-0230
Firefox 1.0 does not prevent the user from dragging an executable file ...
CVE-2005-0142
Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF.
CVE-2005-0144
Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks.
CVE-2005-1159
The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type.
CVE-2005-1155
The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking."
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2005-0590 The installation confirmation dialog in Firefox before 1.0.1, Thunderb ... | CVSS2: 5 | 2% Низкий | почти 21 год назад | |
CVE-2005-1153 Firefox before 1.0.3 and Mozilla Suite before 1.7.7, when blocking a p ... | CVSS2: 7.5 | 7% Низкий | почти 21 год назад | |
CVE-2005-1159 The native implementations of InstallTrigger and other functions in Fi ... | CVSS2: 7.5 | 4% Низкий | почти 21 год назад | |
CVE-2005-1157 Firefox before 1.0.3, Mozilla Suite before 1.7.7, and Netscape 7.2 all ... | CVSS2: 7.5 | 9% Низкий | почти 21 год назад | |
CVE-2005-0146 Firefox before 1.0 and Mozilla before 1.7.5 allow remote attackers to ... | CVSS2: 5 | 1% Низкий | почти 21 год назад | |
CVE-2005-0230 Firefox 1.0 does not prevent the user from dragging an executable file ... | CVSS2: 5.1 | 2% Низкий | почти 21 год назад | |
CVE-2005-0142 Firefox 0.9, Thunderbird 0.6 and other versions before 0.9, and Mozilla 1.7 before 1.7.5 save temporary files with world-readable permissions, which allows local users to read certain web content or attachments that belong to other users, e.g. content that is managed by helper applications such as PDF. | CVSS2: 2.1 | 0% Низкий | почти 21 год назад | |
CVE-2005-0144 Firefox before 1.0 and Mozilla before 1.7.5 display the secure site lock icon when a view-source: URL references a secure SSL site while an insecure page is being loaded, which could facilitate phishing attacks. | CVSS2: 2.6 | 1% Низкий | почти 21 год назад | |
CVE-2005-1159 The native implementations of InstallTrigger and other functions in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 do not properly verify the types of objects being accessed, which causes the Javascript interpreter to continue execution at the wrong memory address, which may allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code by passing objects of the wrong type. | CVSS2: 7.5 | 4% Низкий | почти 21 год назад | |
CVE-2005-1155 The favicon functionality in Firefox before 1.0.3 and Mozilla Suite before 1.7.7 allows remote attackers to execute arbitrary code via a <LINK rel="icon"> tag with a javascript: URL in the href attribute, aka "Firelinking." | CVSS2: 7.5 | 36% Средний | почти 21 год назад |
Уязвимостей на страницу