Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 296

nvd логотип

CVE-2008-4068

почти 18 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2008-4068

почти 18 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2008-4067

почти 18 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-4067

почти 18 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4066

почти 18 лет назад

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-4066

почти 18 лет назад

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows r ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4065

почти 18 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-4065

почти 18 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird befo ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-4064

почти 18 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2008-4064

почти 18 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0 ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-4068

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass "restrictions imposed on local HTML files," and obtain sensitive information and prompt users to write this information into a file, via directory traversal sequences in a resource: URI.

CVSS2: 7.8
4%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4068

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 7.8
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4067

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 on Linux allows remote attackers to read arbitrary files via a .. (dot dot) and URL-encoded / (slash) characters in a resource: URI.

CVSS2: 4.3
4%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4067

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.17 a ...

CVSS2: 4.3
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4066

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4066

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows r ...

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4065

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via byte order mark (BOM) characters that are removed from JavaScript code before execution, aka "Stripped BOM characters bug."

CVSS2: 4.3
4%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4065

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird befo ...

CVSS2: 4.3
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4064

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.

CVSS2: 10
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4064

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0 ...

CVSS2: 10
5%
Низкий
почти 18 лет назад

Уязвимостей на страницу


Поделиться