Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

11511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614720232024202520262027

Недавние уязвимости Mozilla Firefox

Количество 15 501

debian логотип

CVE-2023-23602

больше 2 лет назад

A mishandled security check when creating a WebSocket in a WebWorker c ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23601

больше 2 лет назад

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23601

больше 2 лет назад

Navigations were being allowed when dragging a URL from a cross-origin ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23600

больше 2 лет назад

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23600

больше 2 лет назад

Per origin notification permissions were being stored in a way that di ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23599

больше 2 лет назад

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23599

больше 2 лет назад

When copying a network request from the developer tools panel as a cur ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23598

больше 2 лет назад

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23598

больше 2 лет назад

Due to the Firefox GTK wrapper code's use of text/plain for drag data ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23597

больше 2 лет назад

A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This vulnerability affects Firefox < 109.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-23602

A mishandled security check when creating a WebSocket in a WebWorker c ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23601

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23601

Navigations were being allowed when dragging a URL from a cross-origin ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23600

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23600

Per origin notification permissions were being stored in a way that di ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23599

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23599

When copying a network request from the developer tools panel as a cur ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23598

Due to the Firefox GTK wrapper code's use of text/plain for drag data and GTK treating all text/plain MIMEs containing file URLs as being dragged a website could arbitrarily read a file via a call to `DataTransfer.setData`. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-23598

Due to the Firefox GTK wrapper code's use of text/plain for drag data ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-23597

A compromised web child process could disable web security opening restrictions, leading to a new child process being spawned within the `file://` context. Given a reliable exploit primitive, this new process could be exploited again leading to arbitrary file read. This vulnerability affects Firefox < 109.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться