Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 299

debian логотип

CVE-2009-3378

почти 17 лет назад

The oggplay_data_handle_theora_frame function in media/liboggplay/src/ ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-3377

почти 17 лет назад

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-3377

почти 17 лет назад

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-3376

почти 17 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2009-3376

почти 17 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-3375

почти 17 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-3375

почти 17 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-3374

почти 17 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3374

почти 17 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3373

почти 17 лет назад

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2009-3378

The oggplay_data_handle_theora_frame function in media/liboggplay/src/ ...

CVSS2: 9.3
4%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3377

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e24, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 10
5%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3377

Multiple unspecified vulnerabilities in liboggz before cf5feeaab69b05e ...

CVSS2: 10
5%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3376

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, does not properly handle a right-to-left override (aka RLO or U+202E) Unicode character in a download filename, which allows remote attackers to spoof file extensions via a crafted filename, as demonstrated by displaying a non-executable extension for an executable file.

CVSS2: 9.3
3%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3376

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
3%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3375

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

CVSS2: 4.3
2%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3375

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x ...

CVSS2: 4.3
2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
2%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3373

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
16%
Средний
почти 17 лет назад

Уязвимостей на страницу


Поделиться