Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 225

github логотип

GHSA-qqvq-6xgj-jw8g

около 2 лет назад

Electron affected by libvpx's heap buffer overflow in vp8 encoding

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-5217

около 2 лет назад

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-5217

около 2 лет назад

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2023-5217

около 2 лет назад

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2023-06157

около 2 лет назад

Уязвимость функции кодирования в формат VP8 библиотеки libvpx браузера Google Chrome, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.6
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2023:3829-1

около 2 лет назад

Security update for libwebp

EPSS: Критический
github логотип

GHSA-8fw2-629c-5885

около 2 лет назад

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-v567-j6g5-phvx

около 2 лет назад

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7873-qcmm-76jc

около 2 лет назад

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9rpq-jq5j-fhq8

около 2 лет назад

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-qqvq-6xgj-jw8g

Electron affected by libvpx's heap buffer overflow in vp8 encoding

CVSS3: 8.8
5%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
5%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior ...

CVSS3: 8.8
5%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2023-5217

Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
5%
Низкий
около 2 лет назад
fstec логотип
BDU:2023-06157

Уязвимость функции кодирования в формат VP8 библиотеки libvpx браузера Google Chrome, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.6
5%
Низкий
около 2 лет назад
suse-cvrf логотип
SUSE-SU-2023:3829-1

Security update for libwebp

94%
Критический
около 2 лет назад
github логотип
GHSA-8fw2-629c-5885

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
github логотип
GHSA-v567-j6g5-phvx

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-7873-qcmm-76jc

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-9rpq-jq5j-fhq8

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться