Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414520232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 236

debian логотип

CVE-2023-23603

больше 2 лет назад

Regular expressions used to filter out forbidden properties and values ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23602

больше 2 лет назад

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23602

больше 2 лет назад

A mishandled security check when creating a WebSocket in a WebWorker c ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23601

больше 2 лет назад

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23601

больше 2 лет назад

Navigations were being allowed when dragging a URL from a cross-origin ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23600

больше 2 лет назад

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 109.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23600

больше 2 лет назад

Per origin notification permissions were being stored in a way that di ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23599

больше 2 лет назад

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23599

больше 2 лет назад

When copying a network request from the developer tools panel as a cur ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23598

больше 2 лет назад

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to <code>DataTransfer.setData</code>. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-23603

Regular expressions used to filter out forbidden properties and values ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23602

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23602

A mishandled security check when creating a WebSocket in a WebWorker c ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23601

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23601

Navigations were being allowed when dragging a URL from a cross-origin ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23600

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 109.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23600

Per origin notification permissions were being stored in a way that di ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23599

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23599

When copying a network request from the developer tools panel as a cur ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23598

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to <code>DataTransfer.setData</code>. This vulnerability affects Firefox < 109, Thunderbird < 102.7, and Firefox ESR < 102.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться