Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 296

ubuntu логотип

CVE-2007-3285

около 19 лет назад

Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2007-3089

около 19 лет назад

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2007-3089

около 19 лет назад

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2007-3089

около 19 лет назад

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3073

около 19 лет назад

Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.

CVSS2: 7.8
EPSS: Низкий
nvd логотип

CVE-2007-3074

около 19 лет назад

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2007-3072

около 19 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.

CVSS2: 7.1
EPSS: Низкий
debian логотип

CVE-2007-3072

около 19 лет назад

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on ...

CVSS2: 7.1
EPSS: Низкий
debian логотип

CVE-2007-3073

около 19 лет назад

Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earli ...

CVSS2: 7.8
EPSS: Низкий
debian логотип

CVE-2007-3074

около 19 лет назад

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read fi ...

CVSS2: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2007-3285

Mozilla Firefox before 2.0.0.5, when run on Windows, allows remote attackers to bypass file type checks and possibly execute programs via a (1) file:/// or (2) resource: URI with a dangerous extension, followed by a NULL byte (%00) and a safer extension, which causes Firefox to treat the requested file differently than Windows would.

CVSS2: 6.8
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3089

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3089

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write ...

CVSS2: 4.3
3%
Низкий
около 19 лет назад
ubuntu логотип
CVE-2007-3089

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

CVSS2: 4.3
3%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3073

Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.

CVSS2: 7.8
2%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3074

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.

CVSS2: 4.3
1%
Низкий
около 19 лет назад
nvd логотип
CVE-2007-3072

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on Windows allows remote attackers to read arbitrary files via ..%5C (dot dot encoded backslash) sequences in a resource:// URI.

CVSS2: 7.1
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3072

Directory traversal vulnerability in Mozilla Firefox before 2.0.0.4 on ...

CVSS2: 7.1
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3073

Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earli ...

CVSS2: 7.8
2%
Низкий
около 19 лет назад
debian логотип
CVE-2007-3074

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read fi ...

CVSS2: 4.3
1%
Низкий
около 19 лет назад

Уязвимостей на страницу


Поделиться