Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 220

nvd логотип

CVE-2024-2611

больше 1 года назад

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2024-2611

больше 1 года назад

A missing delay on when pointer lock was used could have allowed a mal ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2024-2610

больше 1 года назад

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-2610

больше 1 года назад

Using a markup injection an attacker could have stolen nonce values. T ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-2609

больше 1 года назад

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-2609

больше 1 года назад

The permission prompt input delay could expire while the window is not ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-2608

больше 1 года назад

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.4
EPSS: Низкий
debian логотип

CVE-2024-2608

больше 1 года назад

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and ...

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2024-2607

больше 1 года назад

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2024-2607

больше 1 года назад

Return registers were overwritten which could have allowed an attacker ...

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-2611

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 5.5
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2611

A missing delay on when pointer lock was used could have allowed a mal ...

CVSS3: 5.5
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-2610

Using a markup injection an attacker could have stolen nonce values. This could have been used to bypass strict content security policies. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2610

Using a markup injection an attacker could have stolen nonce values. T ...

CVSS3: 6.1
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-2609

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2609

The permission prompt input delay could expire while the window is not ...

CVSS3: 6.1
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-2608

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2608

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and ...

CVSS3: 8.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-2607

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.1
3%
Низкий
больше 1 года назад
debian логотип
CVE-2024-2607

Return registers were overwritten which could have allowed an attacker ...

CVSS3: 8.1
3%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться