Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 298

redhat логотип

CVE-2009-2408

около 17 лет назад

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2009-2404

около 17 лет назад

Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2010-0220

около 17 лет назад

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.

CVSS2: 5
EPSS: Низкий
redhat логотип

CVE-2009-2654

около 17 лет назад

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2472

около 17 лет назад

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2472

около 17 лет назад

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrappe ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2009-2471

около 17 лет назад

The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2471

около 17 лет назад

The setTimeout function in Mozilla Firefox before 3.0.12 does not prop ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2469

около 17 лет назад

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2469

около 17 лет назад

Mozilla Firefox before 3.0.12 does not properly handle an SVG element ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2009-2408

Mozilla Network Security Services (NSS) before 3.12.3, Firefox before 3.0.13, Thunderbird before 2.0.0.23, and SeaMonkey before 1.1.18 do not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority. NOTE: this was originally reported for Firefox before 3.5.

CVSS2: 4.3
6%
Низкий
около 17 лет назад
redhat логотип
CVE-2009-2404

Heap-based buffer overflow in a regular-expression parser in Mozilla Network Security Services (NSS) before 3.12.3, as used in Firefox, Thunderbird, SeaMonkey, Evolution, Pidgin, and AOL Instant Messenger (AIM), allows remote SSL servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long domain name in the subject's Common Name (CN) field of an X.509 certificate, related to the cert_TestHostName function.

CVSS2: 6.8
4%
Низкий
около 17 лет назад
redhat логотип
CVE-2010-0220

The nsObserverList::FillObserverArray function in xpcom/ds/nsObserverList.cpp in Mozilla Firefox before 3.5.7 allows remote attackers to cause a denial of service (application crash) via a crafted web site that triggers memory consumption and an accompanying Low Memory alert dialog, and also triggers attempted removal of an observer from an empty observers array.

CVSS2: 5
1%
Низкий
около 17 лет назад
redhat логотип
CVE-2009-2654

Mozilla Firefox before 3.0.13, and 3.5.x before 3.5.2, allows remote attackers to spoof the address bar, and possibly conduct phishing attacks, via a crafted web page that calls window.open with an invalid character in the URL, makes document.write calls to the resulting object, and then calls the stop method during the loading of the error page.

CVSS2: 4.3
5%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2472

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."

CVSS2: 4.3
2%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2472

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrappe ...

CVSS2: 4.3
2%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2471

The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.

CVSS2: 10
4%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2471

The setTimeout function in Mozilla Firefox before 3.0.12 does not prop ...

CVSS2: 10
4%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2469

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.

CVSS2: 10
6%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2469

Mozilla Firefox before 3.0.12 does not properly handle an SVG element ...

CVSS2: 10
6%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться