Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2024-5693

больше 1 года назад

Offscreen Canvas did not properly track cross-origin tainting, which c ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-5692

больше 1 года назад

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-5692

больше 1 года назад

On Windows 10, when using the 'Save As' functionality, an attacker cou ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-5691

больше 1 года назад

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2024-5691

больше 1 года назад

By tricking the browser with a `X-Frame-Options` header, a sandboxed i ...

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2024-5690

больше 1 года назад

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-5690

больше 1 года назад

By monitoring the time certain operations take, an attacker could have ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-5689

больше 1 года назад

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-5689

больше 1 года назад

In addition to detecting when a user was taking a screenshot (XXX), a ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-5688

больше 1 года назад

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-5693

Offscreen Canvas did not properly track cross-origin tainting, which c ...

CVSS3: 6.1
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5692

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5692

On Windows 10, when using the 'Save As' functionality, an attacker cou ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5691

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 4.7
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5691

By tricking the browser with a `X-Frame-Options` header, a sandboxed i ...

CVSS3: 4.7
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5690

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 4.3
4%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5690

By monitoring the time certain operations take, an attacker could have ...

CVSS3: 4.3
4%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5689

In addition to detecting when a user was taking a screenshot (XXX), a website was able to overlay the 'My Shots' button that appeared, and direct the user to a replica Firefox Screenshots page that could be used for phishing. This vulnerability affects Firefox < 127.

CVSS3: 4.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-5689

In addition to detecting when a user was taking a screenshot (XXX), a ...

CVSS3: 4.3
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-5688

If a garbage collection was triggered at the right time, a use-after-free could have occurred during object transplant. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVSS3: 8.1
1%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться