Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2005-0592

почти 21 год назад

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefo ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-0587

почти 21 год назад

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious ...

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2005-0585

почти 21 год назад

Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domai ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0585

почти 21 год назад

Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0587

почти 21 год назад

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2005-0592

почти 21 год назад

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-0143

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-0143

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0143

почти 21 год назад

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2005-0401

почти 21 год назад

FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2005-0592

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefo ...

CVSS2: 7.5
3%
Низкий
почти 21 год назад
debian логотип
CVE-2005-0587

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious ...

CVSS3: 6.5
1%
Низкий
почти 21 год назад
debian логотип
CVE-2005-0585

Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domai ...

CVSS2: 2.6
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0585

Firefox before 1.0.1 and Mozilla before 1.7.6 truncates long sub-domains or paths for display, which may allow remote malicious web sites to spoof legitimate sites and facilitate phishing attacks.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0587

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to overwrite arbitrary files by tricking the user into downloading a .LNK (link) file twice, which overwrites the file that was referenced in the first .LNK file.

CVSS3: 6.5
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0592

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.

CVSS2: 7.5
3%
Низкий
почти 21 год назад
nvd логотип
CVE-2005-0143

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
debian логотип
CVE-2005-0143

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon ...

CVSS2: 2.6
1%
Низкий
почти 21 год назад
ubuntu логотип
CVE-2005-0143

Firefox before 1.0 and Mozilla before 1.7.5 display the SSL lock icon when an insecure page loads a binary file from a trusted site, which could facilitate phishing attacks.

CVSS2: 2.6
1%
Низкий
почти 21 год назад
redhat логотип
CVE-2005-0401

FireFox 1.0.1 and Mozilla before 1.7.6 do not sufficiently address all attack vectors for loading chrome files and hijacking drag and drop events, which allows remote attackers to execute arbitrary XUL code by tricking a user into dragging a scrollbar, a variant of CVE-2005-0527, aka "Firescrolling 2."

4%
Низкий
почти 21 год назад

Уязвимостей на страницу


Поделиться