Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

nvd логотип

CVE-2009-3375

почти 17 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-3374

почти 17 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2009-3374

почти 17 лет назад

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2009-3373

почти 17 лет назад

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2009-3373

почти 17 лет назад

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
EPSS: Средний
debian логотип

CVE-2009-3372

почти 17 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2009-3372

почти 17 лет назад

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2009-3371

почти 17 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 all ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-3371

почти 17 лет назад

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-3370

почти 17 лет назад

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote a ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2009-3375

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

CVSS2: 4.3
2%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation i ...

CVSS2: 7.5
2%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3374

The XPCVariant::VariantDataToJS function in the XPCOM implementation in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 does not enforce intended restrictions on interaction between chrome privileged code and objects obtained from remote web sites, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via unspecified method calls, related to "doubly-wrapped objects."

CVSS2: 7.5
2%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3373

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox ...

CVSS2: 10
16%
Средний
почти 17 лет назад
nvd логотип
CVE-2009-3373

Heap-based buffer overflow in the GIF image parser in Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via unspecified vectors.

CVSS2: 10
16%
Средний
почти 17 лет назад
debian логотип
CVE-2009-3372

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey be ...

CVSS2: 9.3
4%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3372

Mozilla Firefox before 3.0.15 and 3.5.x before 3.5.4, and SeaMonkey before 2.0, allows remote attackers to execute arbitrary code via a crafted regular expression in a Proxy Auto-configuration (PAC) file.

CVSS2: 9.3
4%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3371

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 all ...

CVSS2: 10
7%
Низкий
почти 17 лет назад
nvd логотип
CVE-2009-3371

Use-after-free vulnerability in Mozilla Firefox 3.5.x before 3.5.4 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by creating JavaScript web-workers recursively.

CVSS2: 10
7%
Низкий
почти 17 лет назад
debian логотип
CVE-2009-3370

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote a ...

CVSS2: 5
2%
Низкий
почти 17 лет назад

Уязвимостей на страницу


Поделиться