Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

github логотип

GHSA-845f-27fw-gjw9

больше 1 года назад

Malicious websites may have been able to user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-rh22-rcv2-42x3

больше 1 года назад

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-h8gv-f7pf-7c4p

больше 1 года назад

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mjcw-r3mg-3848

больше 1 года назад

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-53mx-8hhc-gmp3

больше 1 года назад

An attacker could have caused memory corruption due to a flaw in Apple's GPU driver; this can be avoided by working around the flaw. *Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-qxf6-g9x3-8w74

больше 1 года назад

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cpxj-fx45-9pgm

больше 1 года назад

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-53976

больше 1 года назад

Under certain circumstances, navigating to a webpage would result in t ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2024-53976

больше 1 года назад

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2024-53975

больше 1 года назад

Accessing a non-secure HTTP site that uses a non-existent port may cau ...

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-845f-27fw-gjw9

Malicious websites may have been able to user intent confirmation through tapjacking. This could have led to users unknowingly approving the launch of external applications, potentially exposing them to underlying vulnerabilities. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-rh22-rcv2-42x3

A crafted URL containing Arabic script and whitespace characters could have hidden the true origin of the page, resulting in a potential spoofing attack. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
github логотип
GHSA-h8gv-f7pf-7c4p

A double-free issue could have occurred in `sec_pkcs7_decoder_start_decrypt()` when handling an error path. Under specific conditions, the same symmetric key could have been freed twice, potentially leading to memory corruption. This vulnerability affects Firefox < 133 and Thunderbird < 133.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-mjcw-r3mg-3848

Enhanced Tracking Protection's Strict mode may have inadvertently allowed a CSP `frame-src` bypass and DOM-based XSS through the Google SafeFrame shim in the Web Compatibility extension. This issue could have exposed users to malicious frames masquerading as legitimate content. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-53mx-8hhc-gmp3

An attacker could have caused memory corruption due to a flaw in Apple's GPU driver; this can be avoided by working around the flaw. *Note: This issue only affected macOS operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Firefox ESR < 115.18, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-qxf6-g9x3-8w74

The executable file warning was not presented when downloading .library-ms files. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-cpxj-fx45-9pgm

An attacker could cause a select dropdown to be shown over another tab; this could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-53976

Under certain circumstances, navigating to a webpage would result in t ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад
nvd логотип
CVE-2024-53976

Under certain circumstances, navigating to a webpage would result in the address missing from the location URL bar, making it unclear what the URL was for the loaded webpage. This vulnerability affects Firefox for iOS < 133.

CVSS3: 5.4
0%
Низкий
больше 1 года назад
debian логотип
CVE-2024-53975

Accessing a non-secure HTTP site that uses a non-existent port may cau ...

CVSS3: 5.4
0%
Низкий
больше 1 года назад

Уязвимостей на страницу


Поделиться