Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 296

nvd логотип

CVE-2007-0008

больше 19 лет назад

Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-0008

больше 19 лет назад

Integer underflow in the SSLv2 support in Mozilla Network Security Ser ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-0779

больше 19 лет назад

GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and ...

CVSS2: 6.4
EPSS: Низкий
debian логотип

CVE-2007-0780

больше 19 лет назад

browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0 ...

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2007-0009

больше 19 лет назад

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Se ...

CVSS2: 6.8
EPSS: Средний
debian логотип

CVE-2007-0778

больше 19 лет назад

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x befo ...

CVSS2: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2007-0008

больше 19 лет назад

Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-0780

больше 19 лет назад

browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2007-0778

больше 19 лет назад

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.

CVSS2: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2007-0009

больше 19 лет назад

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.

CVSS2: 6.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2007-0008

Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.

CVSS2: 6.8
4%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0008

Integer underflow in the SSLv2 support in Mozilla Network Security Ser ...

CVSS2: 6.8
4%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0779

GUI overlay vulnerability in Mozilla Firefox 1.5.x before 1.5.0.10 and ...

CVSS2: 6.4
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0780

browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0 ...

CVSS2: 6.8
2%
Низкий
больше 19 лет назад
debian логотип
CVE-2007-0009

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Se ...

CVSS2: 6.8
50%
Средний
больше 19 лет назад
debian логотип
CVE-2007-0778

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x befo ...

CVSS2: 5.4
3%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0008

Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow.

CVSS2: 6.8
4%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0780

browser.js in Mozilla Firefox 1.5.x before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 uses the requesting URI to identify child windows, which allows remote attackers to conduct cross-site scripting (XSS) attacks by opening a blocked popup originating from a javascript: URI in combination with multiple frames having the same data: URI.

CVSS2: 6.8
2%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0778

The page cache feature in Mozilla Firefox before 1.5.0.10 and 2.x before 2.0.0.2, and SeaMonkey before 1.0.8 can generate hash collisions that cause page data to be appended to the wrong page cache, which allows remote attackers to obtain sensitive information or enable further attack vectors when the target page is reloaded from the cache.

CVSS2: 5.4
3%
Низкий
больше 19 лет назад
ubuntu логотип
CVE-2007-0009

Stack-based buffer overflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, Thunderbird before 1.5.0.10, SeaMonkey before 1.0.8, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via invalid "Client Master Key" length values.

CVSS2: 6.8
50%
Средний
больше 19 лет назад

Уязвимостей на страницу


Поделиться