Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

debian логотип

CVE-2010-2792

около 16 лет назад

Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox al ...

CVSS2: 3.3
EPSS: Низкий
nvd логотип

CVE-2010-2792

около 16 лет назад

Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.

CVSS2: 3.3
EPSS: Низкий
debian логотип

CVE-2010-3131

около 16 лет назад

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 a ...

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2010-3131

около 16 лет назад

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.

CVSS2: 9.3
EPSS: Средний
redhat логотип

CVE-2010-2794

около 16 лет назад

The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.

CVSS2: 2.1
EPSS: Низкий
redhat логотип

CVE-2010-2792

около 16 лет назад

Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.

CVSS2: 3.3
EPSS: Низкий
debian логотип

CVE-2010-2753

около 16 лет назад

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x befo ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2010-2753

около 16 лет назад

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2010-2752

около 16 лет назад

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5 ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-2752

около 16 лет назад

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2010-2792

Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox al ...

CVSS2: 3.3
0%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2792

Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.

CVSS2: 3.3
0%
Низкий
около 16 лет назад
debian логотип
CVE-2010-3131

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 a ...

CVSS2: 9.3
23%
Средний
около 16 лет назад
nvd логотип
CVE-2010-3131

Untrusted search path vulnerability in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 on Windows XP allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same folder as a .htm, .html, .jtx, .mfp, or .eml file.

CVSS2: 9.3
23%
Средний
около 16 лет назад
redhat логотип
CVE-2010-2794

The SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to overwrite arbitrary files via a symlink attack on an unspecified log file.

CVSS2: 2.1
0%
Низкий
около 16 лет назад
redhat логотип
CVE-2010-2792

Race condition in the SPICE (aka spice-xpi) plug-in 2.2 for Firefox allows local users to obtain sensitive information, and conduct man-in-the-middle attacks, by providing a UNIX socket for communication between this plug-in and the client (aka qspice-client) in qspice 0.3.0, and then accessing this socket.

CVSS2: 3.3
0%
Низкий
около 16 лет назад
debian логотип
CVE-2010-2753

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x befo ...

CVSS3: 8.8
7%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2753

Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code via a large selection attribute in a XUL tree element, which triggers a use-after-free.

CVSS3: 8.8
7%
Низкий
около 16 лет назад
debian логотип
CVE-2010-2752

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5 ...

CVSS2: 9.3
10%
Низкий
около 16 лет назад
nvd логотип
CVE-2010-2752

Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x before 3.0.6 and 3.1.x before 3.1.1, and SeaMonkey before 2.0.6 allows remote attackers to execute arbitrary code by placing many Cascading Style Sheets (CSS) values in an array, related to references to external font resources and an inconsistency between 16-bit and 32-bit integers.

CVSS2: 9.3
10%
Низкий
около 16 лет назад

Уязвимостей на страницу


Поделиться