Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2024-26282

больше 2 лет назад

Using an AMP url with a canonical element, an attacker could have exec ...

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2024-26282

больше 2 лет назад

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.

CVSS3: 7.1
EPSS: Низкий
debian логотип

CVE-2024-26281

больше 2 лет назад

Upon scanning a JavaScript URI with the QR code scanner, an attacker c ...

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2024-26281

больше 2 лет назад

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.

CVSS3: 4.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0579-1

больше 2 лет назад

Security update for mozilla-nss

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2024:0578-1

больше 2 лет назад

Security update for mozilla-nss

EPSS: Низкий
github логотип

GHSA-62vc-2f72-vcj3

больше 2 лет назад

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-8q5j-74vg-j4hr

больше 2 лет назад

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-372x-c6rw-v8f9

больше 2 лет назад

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior. *Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mf2m-vhfh-2qjv

больше 2 лет назад

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2024-26282

Using an AMP url with a canonical element, an attacker could have exec ...

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-26282

Using an AMP url with a canonical element, an attacker could have executed JavaScript from an opened bookmarked page. This vulnerability affects Firefox for iOS < 123.

CVSS3: 7.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2024-26281

Upon scanning a JavaScript URI with the QR code scanner, an attacker c ...

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2024-26281

Upon scanning a JavaScript URI with the QR code scanner, an attacker could have executed unauthorized scripts on the current top origin sites in the URL bar. This vulnerability affects Firefox for iOS < 123.

CVSS3: 4.7
0%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0579-1

Security update for mozilla-nss

1%
Низкий
больше 2 лет назад
suse-cvrf логотип
SUSE-SU-2024:0578-1

Security update for mozilla-nss

1%
Низкий
больше 2 лет назад
github логотип
GHSA-62vc-2f72-vcj3

Memory safety bugs present in Firefox 122, Firefox ESR 115.7, and Thunderbird 115.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 8.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-8q5j-74vg-j4hr

A malicious website could have used a combination of exiting fullscreen mode and `requestPointerLock` to cause the user's mouse to be re-positioned unexpectedly, which could have led to user confusion and inadvertently granting permissions they did not intend to grant. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад
github логотип
GHSA-372x-c6rw-v8f9

Incorrect code generation could have led to unexpected numeric conversions and potential undefined behavior. *Note:* This issue only affects 32-bit ARM devices. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-mf2m-vhfh-2qjv

If a website set a large custom cursor, portions of the cursor could have overlapped with the permission dialog, potentially resulting in user confusion and unexpected granted permissions. This vulnerability affects Firefox < 123 and Firefox ESR < 115.8.

CVSS3: 6.1
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться