Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2024-2609

больше 2 лет назад

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-2608

больше 2 лет назад

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and ...

CVSS3: 8.4
EPSS: Низкий
nvd логотип

CVE-2024-2608

больше 2 лет назад

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.4
EPSS: Низкий
debian логотип

CVE-2024-2607

больше 2 лет назад

Return registers were overwritten which could have allowed an attacker ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2024-2607

больше 2 лет назад

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2024-2606

больше 2 лет назад

Passing invalid data could have led to invalid wasm values being creat ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2024-2606

больше 2 лет назад

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2024-2605

больше 2 лет назад

An attacker could have leveraged the Windows Error Reporter to run arb ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2024-2605

больше 2 лет назад

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2023-5388

больше 2 лет назад

NSS was susceptible to a timing side-channel attack when performing RS ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-2609

The permission prompt input delay could expire while the window is not in focus. This makes it vulnerable to clickjacking by malicious websites. This vulnerability affects Firefox < 124, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-2608

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and ...

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-2608

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-2607

Return registers were overwritten which could have allowed an attacker ...

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-2607

Return registers were overwritten which could have allowed an attacker to execute arbitrary code. *Note:* This issue only affected Armv7-A systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-2606

Passing invalid data could have led to invalid wasm values being creat ...

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-2606

Passing invalid data could have led to invalid wasm values being created, such as arbitrary integers turning into pointer values. This vulnerability affects Firefox < 124.

CVSS3: 3.7
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-2605

An attacker could have leveraged the Windows Error Reporter to run arb ...

CVSS3: 5.9
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-2605

An attacker could have leveraged the Windows Error Reporter to run arbitrary code on the system escaping the sandbox. *Note:* This issue only affected Windows operating systems. Other operating systems are unaffected. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVSS3: 5.9
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-5388

NSS was susceptible to a timing side-channel attack when performing RS ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться