Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 225

ubuntu логотип

CVE-2023-34415

больше 2 лет назад

When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on sites that host an "open redirect". Firefox no longer follows HTTP redirects to data: URLs. This vulnerability affects Firefox < 114.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2023-34416

больше 2 лет назад

Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-32216

больше 2 лет назад

Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-32216

больше 2 лет назад

Mozilla developers and community members Ronald Crane, Andrew McCreigh ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-32214

больше 2 лет назад

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-32214

больше 2 лет назад

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-32210

больше 2 лет назад

Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. This vulnerability affects Firefox < 113.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-32210

больше 2 лет назад

Documents were incorrectly assuming an ordering of principal objects w ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-32209

больше 2 лет назад

A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-32209

больше 2 лет назад

A maliciously crafted favicon could have led to an out of memory crash ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2023-34415

When choosing a site-isolated process for a document loaded from a data: URL that was the result of a redirect, Firefox would load that document in the same process as the site that issued the redirect. This bypassed the site-isolation protections against Spectre-like attacks on sites that host an "open redirect". Firefox no longer follows HTTP redirects to data: URLs. This vulnerability affects Firefox < 114.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
ubuntu логотип
CVE-2023-34416

Memory safety bugs present in Firefox 113, Firefox ESR 102.11, and Thunderbird 102.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.12, Firefox < 114, and Thunderbird < 102.12.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-32216

Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-32216

Mozilla developers and community members Ronald Crane, Andrew McCreigh ...

CVSS3: 9.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-32214

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-32214

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-32210

Documents were incorrectly assuming an ordering of principal objects when ensuring we were loading an appropriately privileged principal. In certain circumstances it might have been possible to cause a document to be loaded with a higher privileged principal than intended. This vulnerability affects Firefox < 113.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-32210

Documents were incorrectly assuming an ordering of principal objects w ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-32209

A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-32209

A maliciously crafted favicon could have led to an out of memory crash ...

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться