Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 208

nvd логотип

CVE-2006-2783

около 20 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2785

около 20 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5 ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2783

около 20 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte- ...

CVSS2: 4.3
EPSS: Низкий
debian логотип

CVE-2006-2779

около 20 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers ...

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2006-2784

около 20 лет назад

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows ...

CVSS2: 5.1
EPSS: Низкий
debian логотип

CVE-2006-2780

около 20 лет назад

Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 all ...

CVSS2: 9.3
EPSS: Низкий
debian логотип

CVE-2006-2782

около 20 лет назад

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1 ...

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-2783

около 20 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

CVSS2: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2006-2779

около 20 лет назад

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.

CVSS2: 9.3
EPSS: Низкий
ubuntu логотип

CVE-2006-2784

около 20 лет назад

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.

CVSS2: 5.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2006-2783

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

CVSS2: 4.3
2%
Низкий
около 20 лет назад
debian логотип
CVE-2006-2785

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 1.5 ...

CVSS2: 4.3
2%
Низкий
около 20 лет назад
debian логотип
CVE-2006-2783

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte- ...

CVSS2: 4.3
2%
Низкий
около 20 лет назад
debian логотип
CVE-2006-2779

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers ...

CVSS2: 9.3
7%
Низкий
около 20 лет назад
debian логотип
CVE-2006-2784

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows ...

CVSS2: 5.1
2%
Низкий
около 20 лет назад
debian логотип
CVE-2006-2780

Integer overflow in Mozilla Firefox and Thunderbird before 1.5.0.4 all ...

CVSS2: 9.3
7%
Низкий
около 20 лет назад
debian логотип
CVE-2006-2782

Firefox 1.5.0.2 does not fix all test cases associated with CVE-2006-1 ...

CVSS2: 4.3
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-2783

Mozilla Firefox and Thunderbird before 1.5.0.4 strip the Unicode Byte-order-Mark (BOM) from a UTF-8 page before the page is passed to the parser, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a BOM sequence in the middle of a dangerous tag such as SCRIPT.

CVSS2: 4.3
2%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-2779

Mozilla Firefox and Thunderbird before 1.5.0.4 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via (1) nested <option> tags in a select tag, (2) a DOMNodeRemoved mutation event, (3) "Content-implemented tree views," (4) BoxObjects, (5) the XBL implementation, (6) an iframe that attempts to remove itself, which leads to memory corruption.

CVSS2: 9.3
7%
Низкий
около 20 лет назад
ubuntu логотип
CVE-2006-2784

The PLUGINSPAGE functionality in Mozilla Firefox before 1.5.0.4 allows remote user-assisted attackers to execute privileged code by tricking a user into installing missing plugins and selecting the "Manual Install" button, then using nested javascript: URLs. NOTE: the manual install button is used for downloading software from a remote web site, so this issue would not cross privilege boundaries if the user progresses to the point of installing malicious software from the attacker-controlled site.

CVSS2: 5.1
2%
Низкий
около 20 лет назад

Уязвимостей на страницу


Поделиться