Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

nvd логотип

CVE-2010-3167

около 16 лет назад

The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer vulnerability."

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-3166

около 16 лет назад

Heap-based buffer overflow in the nsTextFrameUtils::TransformText func ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-3166

около 16 лет назад

Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-2770

около 16 лет назад

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2770

около 16 лет назад

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-2769

около 16 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5 ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2769

около 16 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2768

около 16 лет назад

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-2768

около 16 лет назад

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-2767

около 16 лет назад

The navigator.plugins implementation in Mozilla Firefox before 3.5.12 ...

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2010-3167

The nsTreeContentView function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle node removal in XUL trees, which allows remote attackers to execute arbitrary code via vectors involving access to deleted memory, related to a "dangling pointer vulnerability."

CVSS2: 9.3
7%
Низкий
около 16 лет назад
debian логотип
CVE-2010-3166

Heap-based buffer overflow in the nsTextFrameUtils::TransformText func ...

CVSS2: 9.3
6%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-3166

Heap-based buffer overflow in the nsTextFrameUtils::TransformText function in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 might allow remote attackers to execute arbitrary code via a bidirectional text run.

CVSS2: 9.3
6%
Низкий
около 16 лет назад
debian логотип
CVE-2010-2770

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 9.3
4%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2770

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Mac OS X allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted font in a data: URL.

CVSS2: 9.3
4%
Низкий
около 16 лет назад
debian логотип
CVE-2010-2769

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5 ...

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2769

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 allows user-assisted remote attackers to inject arbitrary web script or HTML via a selection that is added to a document in which the designMode property is enabled.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
debian логотип
CVE-2010-2768

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird befo ...

CVSS2: 4.3
2%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2768

Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 do not properly restrict use of the type attribute of an OBJECT element to set a document's charset, which allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms via UTF-7 encoding.

CVSS2: 4.3
2%
Низкий
около 16 лет назад
debian логотип
CVE-2010-2767

The navigator.plugins implementation in Mozilla Firefox before 3.5.12 ...

CVSS2: 9.3
5%
Низкий
около 16 лет назад

Уязвимостей на страницу


Поделиться