Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 296

nvd логотип

CVE-2008-4063

почти 18 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2008-4063

почти 18 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0 ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2008-4062

почти 18 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2008-4062

почти 18 лет назад

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.1 ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-4061

почти 18 лет назад

Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attribute, related to the layout engine.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2008-4061

почти 18 лет назад

Integer overflow in the MathML component in Mozilla Firefox before 2.0 ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-4060

почти 18 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-4060

почти 18 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird befo ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-4059

почти 18 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-4059

почти 18 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remo ...

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-4063

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the layout engine and (1) a zero value of the "this" variable in the nsContentList::Item function; (2) interaction of the indic IME extension, a Hindi language selection, and the "g" character; and (3) interaction of the nsFrameList::SortByContentOrder function with a certain insufficient protection of inline frames.

CVSS2: 9.3
4%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4063

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0 ...

CVSS2: 9.3
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4062

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the JavaScript engine and (1) misinterpretation of the characteristics of Namespace and QName in jsxml.c, (2) misuse of signed integers in the nsEscapeCount function in nsEscape.cpp, and (3) interaction of JavaScript garbage collection with certain use of an NPObject in the nsNPObjWrapper::GetNewOrUsed function in nsJSNPRuntime.cpp.

CVSS2: 10
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4062

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.1 ...

CVSS2: 10
5%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4061

Integer overflow in the MathML component in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via an mtd element with a large integer value in the rowspan attribute, related to the layout engine.

CVSS2: 10
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4061

Integer overflow in the MathML component in Mozilla Firefox before 2.0 ...

CVSS2: 10
5%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to create documents that lack script-handling objects, and execute arbitrary code with chrome privileges, via vectors related to (1) the document.loadBindingDocument function and (2) XSLT.

CVSS2: 7.5
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4060

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird befo ...

CVSS2: 7.5
5%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
5%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remo ...

CVSS2: 7.5
5%
Низкий
почти 18 лет назад

Уязвимостей на страницу


Поделиться