Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

debian логотип

CVE-2008-5503

почти 18 лет назад

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.1 ...

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2008-5503

почти 18 лет назад

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2008-5502

почти 18 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5502

почти 18 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-5501

почти 18 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2008-5501

почти 18 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2008-5500

почти 18 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2 ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-5500

почти 18 лет назад

The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.

CVSS2: 10
EPSS: Низкий
ubuntu логотип

CVE-2008-5511

почти 18 лет назад

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-5503

почти 18 лет назад

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2008-5503

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.1 ...

CVSS2: 2.6
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5503

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
2%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5502

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5502

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) via vectors that trigger memory corruption, related to the GetXMLEntity and FastAppendChar functions.

CVSS2: 5
2%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5501

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x ...

CVSS2: 5
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5501

The layout engine in Mozilla Firefox 3.x before 3.0.5, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service via vectors that trigger an assertion failure.

CVSS2: 5
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5500

The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2 ...

CVSS2: 10
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5500

The layout engine in Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to cause a denial of service (crash) and possibly trigger memory corruption via vectors related to (1) a reachable assertion or (2) an integer overflow.

CVSS2: 10
3%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-5511

Mozilla Firefox 3.x before 3.0.5 and 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 allows remote attackers to bypass the same origin policy and conduct cross-site scripting (XSS) attacks via an XBL binding to an "unloaded document."

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-5503

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

CVSS2: 2.6
2%
Низкий
почти 18 лет назад

Уязвимостей на страницу


Поделиться