Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2025-0239

больше 1 года назад

When using Alt-Svc, ALPN did not properly validate certificates when t ...

CVSS3: 4
EPSS: Низкий
nvd логотип

CVE-2025-0239

больше 1 года назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 4
EPSS: Низкий
debian логотип

CVE-2025-0238

больше 1 года назад

Assuming a controlled failed memory allocation, an attacker could have ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-0238

больше 1 года назад

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Firefox ESR 115.19, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-0237

больше 1 года назад

The WebChannel API, which is used to transport various information acr ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2025-0237

больше 1 года назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2025-0239

больше 1 года назад

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 4
EPSS: Низкий
ubuntu логотип

CVE-2025-0247

больше 1 года назад

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2025-0244

больше 1 года назад

When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2025-0237

больше 1 года назад

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2025-0239

When using Alt-Svc, ALPN did not properly validate certificates when t ...

CVSS3: 4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0239

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2025-0238

Assuming a controlled failed memory allocation, an attacker could have ...

CVSS3: 5.3
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0238

Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Firefox ESR 115.19, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 5.3
1%
Низкий
больше 1 года назад
debian логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information acr ...

CVSS3: 5.4
1%
Низкий
больше 1 года назад
nvd логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 5.4
1%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-0239

When using Alt-Svc, ALPN did not properly validate certificates when the original server is redirecting to an insecure site. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 4
0%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-0247

Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 134 and Thunderbird 134.

CVSS3: 9.8
9%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-0244

When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.*. This vulnerability was fixed in Firefox 134.

CVSS3: 5.3
7%
Низкий
больше 1 года назад
ubuntu логотип
CVE-2025-0237

The WebChannel API, which is used to transport various information across processes, did not check the sending principal but rather accepted the principal being sent. This could have led to privilege escalation attacks. This vulnerability was fixed in Firefox 134, Firefox ESR 128.6, Thunderbird 134, and Thunderbird 128.6.

CVSS3: 5.4
1%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться