Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

128129130131132133134135136137138139140202420252026

Недавние уязвимости Mozilla Firefox

Количество 14 603

fstec логотип

BDU:2025-00199

7 месяцев назад

Уязвимость браузера Mozilla Firefox и почтового клиента Thunderbird операционных систем Android, связанная с некорректным ограничением визуализированных слоев пользовательского интерфейса, позволяющая нарушителю выполнить атаку типа tapjacking

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-8w77-hpx9-8fm3

8 месяцев назад

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10941

8 месяцев назад

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10941

8 месяцев назад

A malicious website could have included an iframe with an malformed UR ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2024-10941

8 месяцев назад

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2024-10941

8 месяцев назад

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-6rc3-wcpj-59ch

8 месяцев назад

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9v98-vwhg-6x24

8 месяцев назад

Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xhw3-h8gq-2w23

8 месяцев назад

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-4wjh-chq6-qh88

8 месяцев назад

By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
fstec логотип
BDU:2025-00199

Уязвимость браузера Mozilla Firefox и почтового клиента Thunderbird операционных систем Android, связанная с некорректным ограничением визуализированных слоев пользовательского интерфейса, позволяющая нарушителю выполнить атаку типа tapjacking

CVSS3: 8.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-8w77-hpx9-8fm3

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-10941

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10941

A malicious website could have included an iframe with an malformed UR ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
ubuntu логотип
CVE-2024-10941

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
redhat логотип
CVE-2024-10941

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 3.1
0%
Низкий
8 месяцев назад
github логотип
GHSA-6rc3-wcpj-59ch

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 7.5
0%
Низкий
8 месяцев назад
github логотип
GHSA-9v98-vwhg-6x24

Memory safety bugs present in Firefox 131, Firefox ESR 128.3, and Thunderbird 128.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-xhw3-h8gq-2w23

Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-4wjh-chq6-qh88

By sending a specially crafted push message, a remote server could have hung the parent process, causing the browser to become unresponsive. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 7.5
0%
Низкий
8 месяцев назад

Уязвимостей на страницу


Поделиться