Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

nvd логотип

CVE-2009-2472

около 17 лет назад

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2009-2471

около 17 лет назад

The setTimeout function in Mozilla Firefox before 3.0.12 does not prop ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2471

около 17 лет назад

The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2469

около 17 лет назад

Mozilla Firefox before 3.0.12 does not properly handle an SVG element ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2469

около 17 лет назад

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2468

около 17 лет назад

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2467

около 17 лет назад

Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attac ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2467

около 17 лет назад

Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2009-2466

около 17 лет назад

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2009-2466

около 17 лет назад

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2009-2472

Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."

CVSS2: 4.3
2%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2471

The setTimeout function in Mozilla Firefox before 3.0.12 does not prop ...

CVSS2: 10
4%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2471

The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.

CVSS2: 10
4%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2469

Mozilla Firefox before 3.0.12 does not properly handle an SVG element ...

CVSS2: 10
6%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2469

Mozilla Firefox before 3.0.12 does not properly handle an SVG element that has a property with a watch function and an __defineSetter__ function, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted document, related to a certain pointer misinterpretation.

CVSS2: 10
6%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2468

Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.

CVSS2: 10
6%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2467

Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attac ...

CVSS2: 10
5%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2467

Mozilla Firefox before 3.0.12 and 3.5 before 3.5.1 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors involving a Flash object, a slow script dialog, and the unloading of the Flash plugin, which triggers attempted use of a deleted object.

CVSS2: 10
5%
Низкий
около 17 лет назад
debian логотип
CVE-2009-2466

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird ...

CVSS2: 10
7%
Низкий
около 17 лет назад
nvd логотип
CVE-2009-2466

The JavaScript engine in Mozilla Firefox before 3.0.12 and Thunderbird allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to (1) nsDOMClassInfo.cpp, (2) JS_HashTableRawLookup, and (3) MirrorWrappedNativeParent and js_LockGCThingRT.

CVSS2: 10
7%
Низкий
около 17 лет назад

Уязвимостей на страницу


Поделиться