Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2024-10465

почти 2 года назад

A clipboard "paste" button could persist across tabs which allowed a s ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10465

почти 2 года назад

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10464

почти 2 года назад

Repeated writes to history interface attributes could have been used t ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10464

почти 2 года назад

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10463

почти 2 года назад

Video frames could have been leaked between origins in some situations ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10463

почти 2 года назад

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10462

почти 2 года назад

Truncation of a long URL could have allowed origin spoofing in a permi ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10462

почти 2 года назад

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10461

почти 2 года назад

In multipart/x-mixed-replace responses, `Content-Disposition: attachme ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-10461

почти 2 года назад

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-10465

A clipboard "paste" button could persist across tabs which allowed a s ...

CVSS3: 6.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-10465

A clipboard "paste" button could persist across tabs which allowed a spoofing attack. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-10464

Repeated writes to history interface attributes could have been used t ...

CVSS3: 6.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-10464

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-10463

Video frames could have been leaked between origins in some situations ...

CVSS3: 6.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-10463

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-10462

Truncation of a long URL could have allowed origin spoofing in a permi ...

CVSS3: 6.5
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-10462

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-10461

In multipart/x-mixed-replace responses, `Content-Disposition: attachme ...

CVSS3: 6.1
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-10461

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.1
1%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться