Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 296

nvd логотип

CVE-2008-2803

около 18 лет назад

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving third-party add-ons.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2008-2811

около 18 лет назад

The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-2800

около 18 лет назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-2806

около 18 лет назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-2810

около 18 лет назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2008-2806

около 18 лет назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-2803

около 18 лет назад

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox befor ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2008-2800

около 18 лет назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remo ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-2807

около 18 лет назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not pro ...

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-2805

около 18 лет назад

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remo ...

CVSS2: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-2803

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 does not apply XPCNativeWrappers to scripts loaded from (1) file: URIs, (2) data: URIs, or (3) certain non-canonical chrome: URIs, which allows remote attackers to execute arbitrary code via vectors involving third-party add-ons.

CVSS2: 6.8
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2811

The block reflow implementation in Mozilla Firefox before 2.0.0.15, Thunderbird 2.0.0.14 and earlier, and SeaMonkey before 1.1.10 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image whose display requires more pixels than nscoord_MAX, related to nsBlockFrame::DrainOverflowLines.

CVSS2: 10
7%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2800

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via vectors involving (1) an event handler attached to an outer window, (2) a SCRIPT element in an unloaded document, or (3) the onreadystatechange handler in conjunction with an XMLHttpRequest.

CVSS2: 4.3
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2806

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS X allow remote attackers to bypass the Same Origin Policy and create arbitrary socket connections via a crafted Java applet, related to the Java Embedding Plugin (JEP) and Java LiveConnect.

CVSS2: 7.5
3%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2810

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly identify the context of Windows shortcut files, which allows user-assisted remote attackers to bypass the Same Origin Policy via a crafted web site for which the user has previously saved a shortcut.

CVSS2: 6.8
1%
Низкий
около 18 лет назад
debian логотип
CVE-2008-2806

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 on Mac OS ...

CVSS2: 7.5
3%
Низкий
около 18 лет назад
debian логотип
CVE-2008-2803

The mozIJSSubScriptLoader.LoadScript function in Mozilla Firefox befor ...

CVSS2: 6.8
3%
Низкий
около 18 лет назад
debian логотип
CVE-2008-2800

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remo ...

CVSS2: 4.3
2%
Низкий
около 18 лет назад
debian логотип
CVE-2008-2807

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not pro ...

CVSS2: 5
2%
Низкий
около 18 лет назад
debian логотип
CVE-2008-2805

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 allow remo ...

CVSS2: 5
2%
Низкий
около 18 лет назад

Уязвимостей на страницу


Поделиться