Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 225

github логотип

GHSA-rj59-6cjh-fxcf

больше 2 лет назад

In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-gjqm-928w-fr7f

больше 2 лет назад

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116 and Firefox ESR < 115.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-rmgx-g94r-75jg

больше 2 лет назад

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-4053

больше 2 лет назад

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-4053

больше 2 лет назад

A website could have obscured the full screen notification by using a ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-4052

больше 2 лет назад

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-4052

больше 2 лет назад

The Firefox updater created a directory writable by non-privileged use ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-4051

больше 2 лет назад

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-4051

больше 2 лет назад

A website could have obscured the full screen notification by using th ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-4050

больше 2 лет назад

In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-rj59-6cjh-fxcf

In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
8%
Низкий
больше 2 лет назад
github логотип
GHSA-gjqm-928w-fr7f

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116 and Firefox ESR < 115.1.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-rmgx-g94r-75jg

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4053

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4053

A website could have obscured the full screen notification by using a ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4052

The Firefox updater created a directory writable by non-privileged users. When uninstalling Firefox, any files in that directory would be recursively deleted with the permissions of the uninstalling user account. This could be combined with creation of a junction (a form of symbolic link) to allow arbitrary file deletion controlled by the non-privileged user. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 116, Firefox ESR < 115.1, and Thunderbird < 115.1.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4052

The Firefox updater created a directory writable by non-privileged use ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4051

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4051

A website could have obscured the full screen notification by using th ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4050

In some cases, an untrusted input stream was copied to a stack buffer without checking its size. This resulted in a potentially exploitable crash which could have led to a sandbox escape. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
8%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться