Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

debian логотип

CVE-2010-1121

больше 16 лет назад

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2010-1121

больше 16 лет назад

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2010-0172

больше 16 лет назад

toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the as ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-0172

больше 16 лет назад

toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-0171

больше 16 лет назад

Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x bef ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-0171

больше 16 лет назад

Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-0170

больше 16 лет назад

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected w ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2010-0170

больше 16 лет назад

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2010-0169

больше 16 лет назад

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoade ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2010-0169

больше 16 лет назад

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2010-1121

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes ...

CVSS2: 10
6%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-1121

Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving improper interaction with garbage collection, as demonstrated by Nils during a Pwn2Own competition at CanSecWest 2010.

CVSS2: 10
6%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-0172

toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the as ...

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0172

toolkit/components/passwordmgr/src/nsLoginManagerPrompter.js in the asynchronous Authorization Prompt implementation in Mozilla Firefox 3.6 before 3.6.2 does not properly handle concurrent authorization requests from multiple web sites, which might allow remote web servers to spoof an authorization dialog and capture credentials by demanding HTTP authentication in opportunistic circumstances.

CVSS2: 4.3
1%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-0171

Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x bef ...

CVSS2: 4.3
2%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0171

Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allow remote attackers to perform cross-origin keystroke capture, and possibly conduct cross-site scripting (XSS) attacks, by using the addEventListener and setTimeout functions in conjunction with a wrapped object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2007-3736.

CVSS2: 4.3
2%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-0170

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected w ...

CVSS2: 4.3
2%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0170

Mozilla Firefox 3.6 before 3.6.2 does not offer plugins the expected window.location protection mechanism, which might allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors that are specific to each affected plugin.

CVSS2: 4.3
2%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-0169

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoade ...

CVSS2: 5
2%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0169

The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser's font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.

CVSS2: 5
2%
Низкий
больше 16 лет назад

Уязвимостей на страницу


Поделиться