Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

nvd логотип

CVE-2008-3837

почти 18 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2008-3836

почти 18 лет назад

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3836

почти 18 лет назад

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-3835

почти 18 лет назад

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox befor ...

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2008-3835

почти 18 лет назад

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-0016

почти 18 лет назад

Stack-based buffer overflow in the URL parsing implementation in Mozil ...

CVSS2: 10
EPSS: Средний
nvd логотип

CVE-2008-0016

почти 18 лет назад

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

CVSS2: 10
EPSS: Средний
ubuntu логотип

CVE-2008-3837

почти 18 лет назад

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2008-4066

почти 18 лет назад

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-4059

почти 18 лет назад

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2008-3837

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

CVSS2: 9.3
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-3836

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers ...

CVSS2: 7.5
3%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-3836

feedWriter in Mozilla Firefox before 2.0.0.17 allows remote attackers to execute scripts with chrome privileges via vectors related to feed preview and the (1) elem.doCommand, (2) elem.dispatchEvent, (3) _setTitleText, (4) _setTitleImage, and (5) _initSubscriptionUI functions.

CVSS2: 7.5
3%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-3835

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox befor ...

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
nvd логотип
CVE-2008-3835

The nsXMLDocument::OnChannelRedirect function in Mozilla Firefox before 2.0.0.17, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allows remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code via unknown vectors.

CVSS2: 7.5
2%
Низкий
почти 18 лет назад
debian логотип
CVE-2008-0016

Stack-based buffer overflow in the URL parsing implementation in Mozil ...

CVSS2: 10
44%
Средний
почти 18 лет назад
nvd логотип
CVE-2008-0016

Stack-based buffer overflow in the URL parsing implementation in Mozilla Firefox before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to execute arbitrary code via a crafted UTF-8 URL in a link.

CVSS2: 10
44%
Средний
почти 18 лет назад
ubuntu логотип
CVE-2008-3837

Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, and SeaMonkey before 1.1.12, allow user-assisted remote attackers to move a window during a mouse click, and possibly force a file download or unspecified other drag-and-drop action, via a crafted onmousedown action that calls window.moveBy, a variant of CVE-2003-0823.

CVSS2: 9.3
3%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-4066

Mozilla Firefox 2.0.0.14, and other versions before 2.0.0.17, allows remote attackers to bypass cross-site scripting (XSS) protection mechanisms and conduct XSS attacks via HTML-escaped low surrogate characters that are ignored by the HTML parser, as demonstrated by a "jav&#56325ascript" sequence, aka "HTML escaped low surrogates bug."

CVSS2: 4.3
2%
Низкий
почти 18 лет назад
ubuntu логотип
CVE-2008-4059

The XPConnect component in Mozilla Firefox before 2.0.0.17 allows remote attackers to "pollute XPCNativeWrappers" and execute arbitrary code with chrome privileges via vectors related to a SCRIPT element.

CVSS2: 7.5
5%
Низкий
почти 18 лет назад

Уязвимостей на страницу


Поделиться