Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 225

debian логотип

CVE-2023-5174

около 2 лет назад

If Windows failed to duplicate a handle during process creation, the s ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-5173

около 2 лет назад

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-5173

около 2 лет назад

In a non-standard configuration of Firefox, an integer overflow could ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-5172

около 2 лет назад

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-5172

около 2 лет назад

A hashtable in the Ion Engine could have been mutated while there was ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-5171

около 2 лет назад

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-5171

около 2 лет назад

During Ion compilation, a Garbage Collection could have resulted in a ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-5170

около 2 лет назад

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2023-5170

около 2 лет назад

In canvas rendering, a compromised content process could have caused a ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2023-5169

около 2 лет назад

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-5174

If Windows failed to duplicate a handle during process creation, the s ...

CVSS3: 9.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5173

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5173

In a non-standard configuration of Firefox, an integer overflow could ...

CVSS3: 7.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5172

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5172

A hashtable in the Ion Engine could have been mutated while there was ...

CVSS3: 9.8
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5171

During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5171

During Ion compilation, a Garbage Collection could have resulted in a ...

CVSS3: 6.5
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5170

In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.

CVSS3: 7.4
0%
Низкий
около 2 лет назад
debian логотип
CVE-2023-5170

In canvas rendering, a compromised content process could have caused a ...

CVSS3: 7.4
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-5169

A compromised content process could have provided malicious data in a `PathRecording` resulting in an out-of-bounds write, leading to a potentially exploitable crash in a privileged process. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться