Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

github логотип

GHSA-phcc-6pmp-qw9v

больше 1 года назад

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-p4q7-g7ff-823j

больше 1 года назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-f3xq-g93v-w8cv

больше 1 года назад

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 4
EPSS: Низкий
github логотип

GHSA-2776-h8x3-vrr7

больше 1 года назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2025-0247

больше 1 года назад

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2025-0247

больше 1 года назад

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2025-0246

больше 1 года назад

When using an invalid protocol scheme, an attacker could spoof the add ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2025-0246

больше 1 года назад

When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability was fixed in Firefox 134.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2025-0245

больше 1 года назад

Under certain circumstances, a user opt-in setting that Focus should r ...

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2025-0245

больше 1 года назад

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability was fixed in Firefox 134.

CVSS3: 3.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-phcc-6pmp-qw9v

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
github логотип
GHSA-p4q7-g7ff-823j

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 4
0%
Низкий
больше 1 года назад
github логотип
GHSA-f3xq-g93v-w8cv

Parsing a JavaScript module as JSON could, under some circumstances, cause cross-compartment access, which may result in a use-after-free. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 4
1%
Низкий
больше 1 года назад
github логотип
GHSA-2776-h8x3-vrr7

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability affects Firefox < 134 and Firefox ESR < 128.6.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
debian логотип
CVE-2025-0247

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of ...

CVSS3: 9.8
9%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0247

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.

CVSS3: 9.8
9%
Низкий
больше 1 года назад
debian логотип
CVE-2025-0246

When using an invalid protocol scheme, an attacker could spoof the add ...

CVSS3: 6.5
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0246

When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability was fixed in Firefox 134.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-0245

Under certain circumstances, a user opt-in setting that Focus should r ...

CVSS3: 3.3
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0245

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability was fixed in Firefox 134.

CVSS3: 3.3
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться