Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 673

debian логотип

CVE-2008-3444

около 18 лет назад

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows r ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2008-3444

около 18 лет назад

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2008-3444

около 18 лет назад

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."

CVSS2: 4.3
EPSS: Низкий
redhat логотип

CVE-2007-3845

около 18 лет назад

Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2008-2934

около 18 лет назад

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2008-2934

около 18 лет назад

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2008-2934

около 18 лет назад

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2008-3198

около 18 лет назад

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arb ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2008-2933

около 18 лет назад

Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2008-2933

около 18 лет назад

Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.

CVSS2: 2.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2008-3444

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows r ...

CVSS2: 4.3
2%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-3444

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."

CVSS2: 4.3
2%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-3444

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."

CVSS2: 4.3
2%
Низкий
около 18 лет назад
redhat логотип
CVE-2007-3845

Mozilla Firefox before 2.0.0.6, Thunderbird before 1.5.0.13 and 2.x before 2.0.0.6, and SeaMonkey before 1.1.4 allow remote attackers to execute arbitrary commands via certain vectors associated with launching "a file handling program based on the file extension at the end of the URI," a variant of CVE-2007-4041. NOTE: the vendor states that "it is still possible to launch a filetype handler based on extension rather than the registered protocol handler."

CVSS3: 8.8
6%
Низкий
около 18 лет назад
debian логотип
CVE-2008-2934

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to ...

CVSS3: 8.8
4%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-2934

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

CVSS3: 8.8
4%
Низкий
около 18 лет назад
nvd логотип
CVE-2008-2934

Mozilla Firefox 3 before 3.0.1 on Mac OS X allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted GIF file that triggers a free of an uninitialized pointer.

CVSS3: 8.8
4%
Низкий
около 18 лет назад
debian логотип
CVE-2008-3198

Mozilla Firefox 3.x before 3.0.1 allows remote attackers to inject arb ...

CVSS2: 7.5
3%
Низкий
около 18 лет назад
debian логотип
CVE-2008-2933

Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' ...

CVSS2: 2.6
3%
Низкий
около 18 лет назад
ubuntu логотип
CVE-2008-2933

Mozilla Firefox before 2.0.0.16, and 3.x before 3.0.1, interprets '|' (pipe) characters in a command-line URI as requests to open multiple tabs, which allows remote attackers to access chrome:i URIs, or read arbitrary local files via manipulations involving a series of URIs that is not entirely handled by a vector application, as exploited in conjunction with CVE-2008-2540. NOTE: this issue exists because of an insufficient fix for CVE-2005-2267.

CVSS2: 2.6
3%
Низкий
около 18 лет назад

Уязвимостей на страницу


Поделиться