Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2024-6603

около 2 лет назад

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2024-6602

около 2 лет назад

A mismatch between allocator and deallocator could have led to memory ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-6602

около 2 лет назад

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-6601

около 2 лет назад

A race condition could lead to a cross-origin container obtaining perm ...

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2024-6601

около 2 лет назад

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2024-6600

около 2 лет назад

Due to large allocation checks in Angle for GLSL shaders being too len ...

CVSS3: 6.3
EPSS: Низкий
nvd логотип

CVE-2024-6600

около 2 лет назад

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 6.3
EPSS: Низкий
ubuntu логотип

CVE-2024-6610

около 2 лет назад

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2024-6607

около 2 лет назад

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `&lt;select&gt;` element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2024-6605

около 2 лет назад

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-6603

In an out-of-memory scenario an allocation could fail but free would have been called on the pointer afterwards leading to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 7.4
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-6602

A mismatch between allocator and deallocator could have led to memory ...

CVSS3: 9.8
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-6602

A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-6601

A race condition could lead to a cross-origin container obtaining perm ...

CVSS3: 4.7
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-6601

A race condition could lead to a cross-origin container obtaining permissions of the top-level origin. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 4.7
0%
Низкий
около 2 лет назад
debian логотип
CVE-2024-6600

Due to large allocation checks in Angle for GLSL shaders being too len ...

CVSS3: 6.3
0%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-6600

Due to large allocation checks in Angle for GLSL shaders being too lenient an out-of-bounds access could occur when allocating more than 8192 ints in private shader memory on macOS. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

CVSS3: 6.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-6610

Form validation popups could capture escape key presses. Therefore, spamming form validation messages could be used to prevent users from exiting full-screen mode. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-6607

It was possible to prevent a user from exiting pointerlock when pressing escape and to overlay customValidity notifications from a `&lt;select&gt;` element over certain permission prompts. This could be used to confuse a user into giving a site unintended permissions. This vulnerability affects Firefox < 128 and Thunderbird < 128.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
ubuntu логотип
CVE-2024-6605

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

CVSS3: 8.8
0%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться