Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 208

debian логотип

CVE-2005-1575

около 21 года назад

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 5
EPSS: Низкий
nvd логотип

CVE-2005-1576

около 21 года назад

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.

CVSS2: 2.6
EPSS: Низкий
nvd логотип

CVE-2005-1532

около 21 года назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1531

около 21 года назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-1532

около 21 года назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly li ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-1531

около 21 года назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly ...

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2005-1576

около 21 года назад

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-1532

около 21 года назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2005-1531

около 21 года назад

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
EPSS: Низкий
nvd логотип

CVE-2005-1477

около 21 года назад

The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.

CVSS2: 5.1
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2005-1575

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 5
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1576

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows uses the Content-Type HTTP header to determine the file type, but saves the original file extension when "Save to Disk" is selected, which allows remote attackers to hide the real file types of downloaded files.

CVSS2: 2.6
1%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1532

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
9%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
3%
Низкий
около 21 года назад
debian логотип
CVE-2005-1532

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly li ...

CVSS2: 7.5
9%
Низкий
около 21 года назад
debian логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly ...

CVSS2: 7.5
3%
Низкий
около 21 года назад
debian логотип
CVE-2005-1576

The file download dialog in Mozilla Firefox 0.10.1 and 1.0 for Windows ...

CVSS2: 2.6
1%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-1532

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 do not properly limit privileges of Javascript eval and Script objects in the calling context, which allows remote attackers to conduct unauthorized activities via "non-DOM property overrides," a variant of CVE-2005-1160.

CVSS2: 7.5
9%
Низкий
около 21 года назад
ubuntu логотип
CVE-2005-1531

Firefox before 1.0.4 and Mozilla Suite before 1.7.8 does not properly implement certain security checks for script injection, which allows remote attackers to execute script via "Wrapped" javascript: URLs, as demonstrated using (1) a javascript: URL in a view-source: URL, (2) a javascript: URL in a jar: URL, or (3) "a nested variant."

CVSS2: 7.5
3%
Низкий
около 21 года назад
nvd логотип
CVE-2005-1477

The install function in Firefox 1.0.3 allows remote web sites on the browser's whitelist, such as update.mozilla.org or addon.mozilla.org, to execute arbitrary Javascript with chrome privileges, leading to arbitrary code execution on the system when combined with vulnerabilities such as CVE-2005-1476, as demonstrated using a javascript: URL as the package icon and a cross-site scripting (XSS) attack on a vulnerable whitelist site.

CVSS2: 5.1
15%
Средний
около 21 года назад

Уязвимостей на страницу


Поделиться