Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

debian логотип

CVE-2010-0168

больше 16 лет назад

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocum ...

CVSS2: 7.6
EPSS: Средний
nvd логотип

CVE-2010-0168

больше 16 лет назад

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.

CVSS2: 7.6
EPSS: Средний
debian логотип

CVE-2010-0167

больше 16 лет назад

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x befor ...

CVSS2: 9.3
EPSS: Средний
nvd логотип

CVE-2010-0167

больше 16 лет назад

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.

CVSS2: 9.3
EPSS: Средний
debian логотип

CVE-2010-0166

больше 16 лет назад

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.c ...

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2010-0166

больше 16 лет назад

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2010-0165

больше 16 лет назад

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-0165

больше 16 лет назад

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2010-0164

больше 16 лет назад

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelp ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2010-0164

больше 16 лет назад

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.

CVSS2: 9.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2010-0168

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocum ...

CVSS2: 7.6
12%
Средний
больше 16 лет назад
nvd логотип
CVE-2010-0168

The nsDocument::MaybePreLoadImage function in content/base/src/nsDocument.cpp in the image-preloading implementation in Mozilla Firefox 3.6 before 3.6.2 does not apply scheme restrictions and policy restrictions to the image's URL, which might allow remote attackers to cause a denial of service (application crash or hang) or hijack the functionality of the browser's add-ons via a crafted SRC attribute of an IMG element, as demonstrated by remote command execution through an ssh: URL in a configuration that supports gnome-vfs with a nonstandard network.gnomevfs.supported-protocols setting.

CVSS2: 7.6
12%
Средний
больше 16 лет назад
debian логотип
CVE-2010-0167

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x befor ...

CVSS2: 9.3
11%
Средний
больше 16 лет назад
nvd логотип
CVE-2010-0167

The browser engine in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors related to (1) layout/generic/nsBlockFrame.cpp and (2) the _evaluate function in modules/plugin/base/src/nsNPAPIPlugin.cpp.

CVSS2: 9.3
11%
Средний
больше 16 лет назад
debian логотип
CVE-2010-0166

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.c ...

CVSS2: 5.1
7%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0166

The gfxTextRun::SanitizeGlyphRuns function in gfx/thebes/src/gfxFont.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 on Mac OS X, when the Core Text API is used, does not properly perform certain deletions, which allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via an HTML document containing invisible Unicode characters, as demonstrated by the U+FEFF, U+FFF9, U+FFFA, and U+FFFB characters.

CVSS2: 5.1
7%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-0165

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp ...

CVSS2: 9.3
4%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0165

The TraceRecorder::traverseScopeChain function in js/src/jstracer.cpp in the browser engine in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly execute arbitrary code via vectors involving certain indirect calls to the JavaScript eval function.

CVSS2: 9.3
4%
Низкий
больше 16 лет назад
debian логотип
CVE-2010-0164

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelp ...

CVSS2: 9.3
6%
Низкий
больше 16 лет назад
nvd логотип
CVE-2010-0164

Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.

CVSS2: 9.3
6%
Низкий
больше 16 лет назад

Уязвимостей на страницу


Поделиться