Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
CVE-2005-0592
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefo ...
CVE-2005-0587
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious ...
CVE-2005-0585
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domai ...
CVE-2005-0585
Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.
CVE-2005-0587
Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.
CVE-2005-0592
Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.
CVE-2005-0143
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
CVE-2005-0143
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon ...
CVE-2005-0143
Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.
CVE-2005-0401
FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2005-0592 Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefo ... | CVSS2: 7.5 | 3% Низкий | почти 21 год назад | |
CVE-2005-0587 Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious ... | CVSS3: 6.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-0585 Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domai ... | CVSS2: 2.6 | 1% Низкий | почти 21 год назад | |
CVE-2005-0585 Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks. | CVSS2: 2.6 | 1% Низкий | почти 21 год назад | |
CVE-2005-0587 Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file. | CVSS3: 6.5 | 1% Низкий | почти 21 год назад | |
CVE-2005-0592 Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value. | CVSS2: 7.5 | 3% Низкий | почти 21 год назад | |
CVE-2005-0143 Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks. | CVSS2: 2.6 | 1% Низкий | почти 21 год назад | |
CVE-2005-0143 Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon ... | CVSS2: 2.6 | 1% Низкий | почти 21 год назад | |
CVE-2005-0143 Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks. | CVSS2: 2.6 | 1% Низкий | почти 21 год назад | |
CVE-2005-0401 FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2." | 4% Низкий | почти 21 год назад |
Уязвимостей на страницу