Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 208

redhat логотип

CVE-2005-0586

больше 21 года назад

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.

EPSS: Низкий
redhat логотип

CVE-2005-0588

больше 21 года назад

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

EPSS: Низкий
redhat логотип

CVE-2005-0592

больше 21 года назад

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.

EPSS: Низкий
nvd логотип

CVE-2005-0233

больше 21 года назад

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

CVSS2: 7.5
EPSS: Средний
debian логотип

CVE-2005-0233

больше 21 года назад

The International Domain Name (IDN) support in Firefox 1.0, Camino .8. ...

CVSS2: 7.5
EPSS: Средний
ubuntu логотип

CVE-2005-0233

больше 21 года назад

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

CVSS2: 7.5
EPSS: Средний
nvd логотип

CVE-2005-0231

больше 21 года назад

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

CVSS2: 2.6
EPSS: Низкий
debian логотип

CVE-2005-0231

больше 21 года назад

Firefox 1.0 does not invoke the Javascript Security Manager when a use ...

CVSS2: 2.6
EPSS: Низкий
ubuntu логотип

CVE-2005-0231

больше 21 года назад

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

CVSS2: 2.6
EPSS: Низкий
redhat логотип

CVE-2005-0232

больше 21 года назад

Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2005-0586

Firefox before 1.0.1 and Mozilla before 1.7.6 allows remote malicious web sites to spoof the extensions of files to download via the Content-Disposition header, which could be used to trick users into downloading dangerous content.

1%
Низкий
больше 21 года назад
redhat логотип
CVE-2005-0588

Firefox before 1.0.1 and Mozilla before 1.7.6 does not restrict xsl:include and xsl:import tags in XSLT stylesheets to the current domain, which allows remote attackers to determine the existence of files on the local system.

2%
Низкий
больше 21 года назад
redhat логотип
CVE-2005-0592

Heap-based buffer overflow in the UTF8ToNewUnicode function for Firefox before 1.0.1 and Mozilla before 1.7.6 might allow remote attackers to cause a denial of service (crash) or execute arbitrary code via invalid sequences in a UTF8 encoded string that result in a zero length value.

4%
Низкий
больше 21 года назад
nvd логотип
CVE-2005-0233

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

CVSS2: 7.5
20%
Средний
больше 21 года назад
debian логотип
CVE-2005-0233

The International Domain Name (IDN) support in Firefox 1.0, Camino .8. ...

CVSS2: 7.5
20%
Средний
больше 21 года назад
ubuntu логотип
CVE-2005-0233

The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certificates in a way that uses homograph characters from other character sets, which facilitates phishing attacks.

CVSS2: 7.5
20%
Средний
больше 21 года назад
nvd логотип
CVE-2005-0231

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

CVSS2: 2.6
3%
Низкий
больше 21 года назад
debian логотип
CVE-2005-0231

Firefox 1.0 does not invoke the Javascript Security Manager when a use ...

CVSS2: 2.6
3%
Низкий
больше 21 года назад
ubuntu логотип
CVE-2005-0231

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

CVSS2: 2.6
3%
Низкий
больше 21 года назад
redhat логотип
CVE-2005-0232

Firefox 1.0 allows remote attackers to modify Boolean configuration parameters for the about:config site by using a plugin such as Flash, and the -moz-opacity filter, to display the about:config site then cause the user to double-click at a certain screen position, aka "Fireflashing."

3%
Низкий
больше 21 года назад

Уязвимостей на страницу


Поделиться