Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 225

nvd логотип

CVE-2023-25740

больше 2 лет назад

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25740

больше 2 лет назад

After downloading a Windows <code>.scf</code> script from the local fi ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25739

больше 2 лет назад

Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25739

больше 2 лет назад

Module load requests that failed were not being checked as to whether ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25738

больше 2 лет назад

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-25738

больше 2 лет назад

Members of the <code>DEVMODEW</code> struct set by the printer device ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-25737

больше 2 лет назад

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25737

больше 2 лет назад

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</ ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25735

больше 2 лет назад

Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25735

больше 2 лет назад

Cross-compartment wrappers wrapping a scripted proxy could have caused ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-25740

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25740

After downloading a Windows <code>.scf</code> script from the local fi ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25739

Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25739

Module load requests that failed were not being checked as to whether ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25738

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25738

Members of the <code>DEVMODEW</code> struct set by the printer device ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25737

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25737

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</ ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25735

Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25735

Cross-compartment wrappers wrapping a scripted proxy could have caused ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться