Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 296

redhat логотип

CVE-2007-3735

около 19 лет назад

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.

EPSS: Низкий
nvd логотип

CVE-2007-3827

около 19 лет назад

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.

CVSS2: 5
EPSS: Низкий
debian логотип

CVE-2007-3827

около 19 лет назад

Mozilla Firefox allows for cookies to be set with a null domain (aka " ...

CVSS2: 5
EPSS: Низкий
ubuntu логотип

CVE-2007-3827

около 19 лет назад

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2007-3657

около 19 лет назад

Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely mechanism of action that would lead to a DoS condition.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3670

около 19 лет назад

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."

CVSS2: 4.3
EPSS: Средний
nvd логотип

CVE-2007-3656

около 19 лет назад

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-3657

около 19 лет назад

Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of s ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-3656

около 19 лет назад

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not pe ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-3670

около 19 лет назад

Argument injection vulnerability in Microsoft Internet Explorer, when ...

CVSS2: 4.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2007-3735

Multiple unspecified vulnerabilities in the JavaScript engine in Mozilla Firefox before 2.0.0.5 and Thunderbird before 2.0.0.5 allow remote attackers to cause a denial of service (crash) via unspecified vectors that trigger memory corruption.

2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3827

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.

CVSS2: 5
1%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3827

Mozilla Firefox allows for cookies to be set with a null domain (aka " ...

CVSS2: 5
1%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-3827

Mozilla Firefox allows for cookies to be set with a null domain (aka "domainless cookies"), which allows remote attackers to pass information between arbitrary domains and track user activity, as demonstrated by the domain attribute in the document.cookie variable in a javascript: window.

CVSS2: 5
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3657

Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of service by opening multiple tabs in a popup window. NOTE: this issue has been disputed by third party researchers, stating that "this does not crash on me, and I can't see a likely mechanism of action that would lead to a DoS condition.

CVSS2: 4.3
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3670

Argument injection vulnerability in Microsoft Internet Explorer, when running on systems with Firefox installed and certain URIs registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in a (1) FirefoxURL or (2) FirefoxHTML URI, which are inserted into the command line that is created when invoking firefox.exe. NOTE: it has been debated as to whether the issue is in Internet Explorer or Firefox. As of 20070711, it is CVE's opinion that IE appears to be failing to properly delimit the URL argument when invoking Firefox, and this issue could arise with other protocol handlers in IE as well. However, Mozilla has stated that it will address the issue with a "defense in depth" fix that will "prevent IE from sending Firefox malicious data."

CVSS2: 4.3
29%
Средний
около 19 лет назад
nvd логотип
CVE-2007-3656

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not perform a security zone check when processing a wyciwyg URI, which allows remote attackers to obtain sensitive information, poison the browser cache, and possibly enable further attack vectors via (1) HTTP 302 redirect controls, (2) XMLHttpRequest, or (3) view-source URIs.

CVSS2: 6.8
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3657

Mozilla Firefox 2.0.0.4 allows remote attackers to cause a denial of s ...

CVSS2: 4.3
1%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3656

Mozilla Firefox before 1.8.0.13 and 1.8.1.x before 1.8.1.5 does not pe ...

CVSS2: 6.8
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3670

Argument injection vulnerability in Microsoft Internet Explorer, when ...

CVSS2: 4.3
29%
Средний
около 19 лет назад

Уязвимостей на страницу


Поделиться