Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 225

debian логотип

CVE-2023-4050

больше 2 лет назад

In some cases, an untrusted input stream was copied to a stack buffer ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-4049

больше 2 лет назад

Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-4049

больше 2 лет назад

Race conditions in reference counting code were found through code ins ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2023-4048

больше 2 лет назад

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-4048

больше 2 лет назад

An out-of-bounds read could have led to an exploitable crash when pars ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-4047

больше 2 лет назад

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-4047

больше 2 лет назад

A bug in popup notifications delay calculation could have made it poss ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-4046

больше 2 лет назад

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-4046

больше 2 лет назад

In some circumstances, a stale value could have been used for a global ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-4045

больше 2 лет назад

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-4050

In some cases, an untrusted input stream was copied to a stack buffer ...

CVSS3: 7.5
8%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4049

Race conditions in reference counting code were found through code inspection. These could have resulted in potentially exploitable use-after-free vulnerabilities. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4049

Race conditions in reference counting code were found through code ins ...

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4048

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4048

An out-of-bounds read could have led to an exploitable crash when pars ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4047

A bug in popup notifications delay calculation could have made it possible for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4047

A bug in popup notifications delay calculation could have made it poss ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4046

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-4046

In some circumstances, a stale value could have been used for a global ...

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-4045

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться