Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 220

debian логотип

CVE-2024-1549

почти 2 года назад

If a website set a large custom cursor, portions of the cursor could h ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-1548

почти 2 года назад

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-1548

почти 2 года назад

A website could have obscured the fullscreen notification by using a d ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-1547

почти 2 года назад

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-1547

почти 2 года назад

Through a series of API calls and redirects, an attacker-controlled al ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-1546

почти 2 года назад

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-1546

почти 2 года назад

When storing and re-accessing data on a networking channel, the length ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-1554

почти 2 года назад

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2024-1555

почти 2 года назад

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

CVSS3: 8.3
EPSS: Низкий
ubuntu логотип

CVE-2024-1548

почти 2 года назад

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-1549

If a website set a large custom cursor, portions of the cursor could h ...

CVSS3: 6.1
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-1548

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 4.3
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-1548

A website could have obscured the fullscreen notification by using a d ...

CVSS3: 4.3
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-1547

Through a series of API calls and redirects, an attacker-controlled alert dialog could have been displayed on another website (with the victim website's URL shown). This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-1547

Through a series of API calls and redirects, an attacker-controlled al ...

CVSS3: 6.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-1546

When storing and re-accessing data on a networking channel, the length of buffers may have been confused, resulting in an out-of-bounds memory read. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 7.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-1546

When storing and re-accessing data on a networking channel, the length ...

CVSS3: 7.5
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-1554

The `fetch()` API and navigation incorrectly shared the same cache, as the cache key did not include the optional headers `fetch()` may contain. Under the correct circumstances, an attacker may have been able to poison the local browser cache by priming it with a `fetch()` response controlled by the additional headers. Upon navigation to the same URL, the user would see the cached response instead of the expected response. This vulnerability affects Firefox < 123.

CVSS3: 9.8
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-1555

When opening a website using the `firefox://` protocol handler, SameSite cookies were not properly respected. This vulnerability affects Firefox < 123.

CVSS3: 8.3
0%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-1548

A website could have obscured the fullscreen notification by using a dropdown select input element. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 123, Firefox ESR < 115.8, and Thunderbird < 115.8.

CVSS3: 4.3
1%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться