Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-6211

больше 2 лет назад

If an attacker needed a user to load an insecure http: page and knew t ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6211

больше 2 лет назад

If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6210

больше 2 лет назад

When an https: web page created a pop-up from a "javascript:" URL, tha ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6210

больше 2 лет назад

When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6209

больше 2 лет назад

Relative URLs starting with three slashes were incorrectly parsed, and ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6209

больше 2 лет назад

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6208

больше 2 лет назад

When using X11, text selected by the page using the Selection API was ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-6208

больше 2 лет назад

When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-6207

больше 2 лет назад

Ownership mismanagement led to a use-after-free in ReadableByteStreams ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-6207

больше 2 лет назад

Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-6211

If an attacker needed a user to load an insecure http: page and knew t ...

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6211

If an attacker needed a user to load an insecure http: page and knew that user had enabled HTTPS-only mode, the attacker could have tricked the user into clicking to grant an HTTPS-only exception if they could get the user to participate in a clicking game. This vulnerability affects Firefox < 120.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6210

When an https: web page created a pop-up from a "javascript:" URL, tha ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6210

When an https: web page created a pop-up from a "javascript:" URL, that pop-up was incorrectly allowed to load blockable content such as iframes from insecure http: URLs This vulnerability affects Firefox < 120.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6209

Relative URLs starting with three slashes were incorrectly parsed, and ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6209

Relative URLs starting with three slashes were incorrectly parsed, and a path-traversal "/../" part in the path could be used to override the specified host. This could contribute to security problems in web sites. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6208

When using X11, text selected by the page using the Selection API was ...

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6208

When using X11, text selected by the page using the Selection API was erroneously copied into the primary selection, a temporary storage not unlike the clipboard. *This bug only affects Firefox on X11. Other systems are unaffected.* This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6207

Ownership mismanagement led to a use-after-free in ReadableByteStreams ...

CVSS3: 8.8
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6207

Ownership mismanagement led to a use-after-free in ReadableByteStreams This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 8.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться