Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 236

debian логотип

CVE-2023-25735

больше 2 лет назад

Cross-compartment wrappers wrapping a scripted proxy could have caused ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25734

больше 2 лет назад

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2023-25734

больше 2 лет назад

After downloading a Windows <code>.url</code> shortcut from the local ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2023-25732

больше 2 лет назад

When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25732

больше 2 лет назад

When encoding data from an <code>inputStream</code> in <code>xpcom</co ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25731

больше 2 лет назад

Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25731

больше 2 лет назад

Due to URL previews in the network panel of developer tools improperly ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25730

больше 2 лет назад

A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-25730

больше 2 лет назад

A background script invoking <code>requestFullscreen</code> and then b ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-25729

больше 2 лет назад

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-25735

Cross-compartment wrappers wrapping a scripted proxy could have caused ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25734

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25734

After downloading a Windows <code>.url</code> shortcut from the local ...

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25732

When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25732

When encoding data from an <code>inputStream</code> in <code>xpcom</co ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25731

Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25731

Due to URL previews in the network panel of developer tools improperly ...

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25730

A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-25730

A background script invoking <code>requestFullscreen</code> and then b ...

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-25729

Permission prompts for opening external schemes were only shown for <code>ContentPrincipals</code> resulting in extensions being able to open them without user interaction via <code>ExpandedPrincipals</code>. This could lead to further malicious actions such as downloading files or interacting with software already installed on the system. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться