Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2024-2608

почти 2 года назад

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.4
EPSS: Низкий
debian логотип

CVE-2024-2608

почти 2 года назад

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and ...

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2024-2607

почти 2 года назад

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2024-2607

почти 2 года назад

Return registers were overwritten which could have allowed an attacker ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-2606

почти 2 года назад

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2024-2606

почти 2 года назад

Passing invalid data could have led to invalid wasm values being creat ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2024-2605

почти 2 года назад

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2024-2605

почти 2 года назад

An attacker could have leveraged the Windows Error Reporter to run arb ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2023-5388

почти 2 года назад

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-5388

почти 2 года назад

NSS was susceptible to a timing side-channel attack when performing RS ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-2608

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.4
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-2608

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and ...

CVSS3: 8.4
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-2607

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.1
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-2607

Return registers were overwritten which could have allowed an attacker ...

CVSS3: 8.1
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-2606

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.

CVSS3: 3.7
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-2606

Passing invalid data could have led to invalid wasm values being creat ...

CVSS3: 3.7
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-2605

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 5.9
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-2605

An attacker could have leveraged the Windows Error Reporter to run arb ...

CVSS3: 5.9
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2023-5388

NSS was susceptible to a timing side-channel attack when performing RSA decryption. This attack could potentially allow an attacker to recover the private data. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
debian логотип
CVE-2023-5388

NSS was susceptible to a timing side-channel attack when performing RS ...

CVSS3: 6.5
0%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться