Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

github логотип

GHSA-w694-6mxx-38mc

больше 2 лет назад

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-38mm-6p5m-rh38

больше 2 лет назад

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-fffc-4hjp-2r9v

больше 2 лет назад

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-68c9-wp52-fpg7

больше 2 лет назад

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-vgc7-vqc6-2858

больше 2 лет назад

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-64f6-885c-52vw

больше 2 лет назад

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-36cp-x9pq-r87w

больше 2 лет назад

The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2fg8-6ggf-j2jg

больше 2 лет назад

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-vp32-xxhm-ppgv

больше 2 лет назад

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-7ggp-cp85-r5cg

больше 2 лет назад

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-w694-6mxx-38mc

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
1%
Низкий
больше 2 лет назад
github логотип
GHSA-38mm-6p5m-rh38

A file dialog shown while in full-screen mode could have resulted in the window remaining disabled. This vulnerability affects Firefox < 126.

CVSS3: 8.2
0%
Низкий
больше 2 лет назад
github логотип
GHSA-fffc-4hjp-2r9v

If the `browser.privatebrowsing.autostart` preference is enabled, IndexedDB files were not properly deleted when the window was closed. This preference is disabled by default in Firefox. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-68c9-wp52-fpg7

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-vgc7-vqc6-2858

When importing resources using Web Workers, error messages would distinguish the difference between `application/javascript` responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-64f6-885c-52vw

An HTTP digest authentication nonce value was generated using `rand()` which could lead to predictable values. This vulnerability affects Firefox < 126.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-36cp-x9pq-r87w

The `ShmemCharMapHashEntry()` code was susceptible to potentially undefined behavior by bypassing the move semantics for one of its data members. This vulnerability affects Firefox < 126.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-2fg8-6ggf-j2jg

A bug in popup notifications' interaction with WebAuthn made it easier for an attacker to trick a user into granting permissions. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-vp32-xxhm-ppgv

Web application manifests were stored by using an insecure MD5 hash which allowed for a hash collision to overwrite another application's manifest. This could have been exploited to run arbitrary code in another application's context. *This issue only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.

CVSS3: 8.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7ggp-cp85-r5cg

When saving a page to PDF, certain font styles could have led to a potential use-after-free crash. This vulnerability affects Firefox < 126, Firefox ESR < 115.11, and Thunderbird < 115.11.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться