Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

nvd логотип

CVE-2008-5023

почти 18 лет назад

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-5022

почти 18 лет назад

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x befor ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-5022

почти 18 лет назад

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-5021

почти 18 лет назад

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1 ...

CVSS2: 9.3
EPSS: Низкий
nvd логотип

CVE-2008-5021

почти 18 лет назад

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2008-5019

почти 18 лет назад

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2. ...

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-5019

почти 18 лет назад

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2008-5018

почти 18 лет назад

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x ...

CVSS2: 10
EPSS: Низкий
nvd логотип

CVE-2008-5018

почти 18 лет назад

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2008-5017

почти 18 лет назад

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Moz ...

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-5023

Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the protection mechanism for codebase principals and execute arbitrary script via the -moz-binding CSS property in a signed JAR file.

CVSS2: 7.5
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x befor ...

CVSS2: 7.5
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5022

The nsXMLHttpRequest::NotifyEventListeners method in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to bypass the same-origin policy and execute arbitrary script via multiple listeners, which bypass the inner window check.

CVSS2: 7.5
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.1 ...

CVSS2: 9.3
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5021

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to access uninitialized memory.

CVSS2: 9.3
4%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5019

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2. ...

CVSS2: 4.3
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5019

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

CVSS2: 4.3
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5018

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x ...

CVSS2: 10
4%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-5018

The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class.

CVSS2: 10
4%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-5017

Integer overflow in xpcom/io/nsEscape.cpp in the browser engine in Moz ...

CVSS2: 10
4%
Низкий
почти 18 лет назад

Уязвимостей на страницу


Поделиться