Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

nvd логотип

CVE-2024-0742

около 2 лет назад

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-0742

около 2 лет назад

It was possible for certain browser prompts and dialogs to be activate ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-0741

около 2 лет назад

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2024-0741

около 2 лет назад

An out of bounds write in ANGLE could have allowed an attacker to corr ...

CVSS3: 6.5
EPSS: Средний
ubuntu логотип

CVE-2024-0745

около 2 лет назад

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2024-0744

около 2 лет назад

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-0743

около 2 лет назад

An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2024-0753

около 2 лет назад

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-0754

около 2 лет назад

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-0747

около 2 лет назад

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-0742

It was possible for certain browser prompts and dialogs to be activated or dismissed unintentionally by the user due to an incorrect timestamp used to prevent input after page load. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 4.3
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-0742

It was possible for certain browser prompts and dialogs to be activate ...

CVSS3: 4.3
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-0741

An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 6.5
43%
Средний
около 2 лет назад
debian логотип
CVE-2024-0741

An out of bounds write in ANGLE could have allowed an attacker to corr ...

CVSS3: 6.5
43%
Средний
около 2 лет назад
ubuntu логотип
CVE-2024-0745

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0744

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0743

An unchecked return value in TLS handshake code could have caused a potentially exploitable crash. This vulnerability affects Firefox < 122, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0753

In specific HSTS configurations an attacker could have bypassed HSTS on a subdomain. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0754

Some WASM source files could have caused a crash when loaded in devtools. This vulnerability affects Firefox < 122.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-0747

When a parent page loaded a child in an iframe with `unsafe-inline`, the parent Content Security Policy could have overridden the child Content Security Policy. This vulnerability affects Firefox < 122, Firefox ESR < 115.7, and Thunderbird < 115.7.

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться