Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-6206

больше 2 лет назад

The black fade animation when exiting fullscreen is roughly the length ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-6206

больше 2 лет назад

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2023-6205

больше 2 лет назад

It was possible to cause the use of a MessagePort after it had already ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6205

больше 2 лет назад

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-6204

больше 2 лет назад

On some systems\u2014depending on the graphics settings and drivers\u2 ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-6204

больше 2 лет назад

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-49061

больше 2 лет назад

An attacker could have performed HTML template injection via Reader Mo ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-49061

больше 2 лет назад

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-49060

больше 2 лет назад

An attacker could have accessed internal pages or data by ex-filtratin ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-49060

больше 2 лет назад

An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-6206

The black fade animation when exiting fullscreen is roughly the length ...

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6206

The black fade animation when exiting fullscreen is roughly the length of the anti-clickjacking delay on permission prompts. It was possible to use this fact to surprise users by luring them to click where the permission grant button would be about to appear. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 5.4
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6205

It was possible to cause the use of a MessagePort after it had already ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6205

It was possible to cause the use of a MessagePort after it had already been freed, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-6204

On some systems\u2014depending on the graphics settings and drivers\u2 ...

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-6204

On some systems—depending on the graphics settings and drivers—it was possible to force an out-of-bounds read and leak memory data into the images created on the canvas element. This vulnerability affects Firefox < 120, Firefox ESR < 115.5.0, and Thunderbird < 115.5.

CVSS3: 6.5
1%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-49061

An attacker could have performed HTML template injection via Reader Mo ...

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-49061

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2023-49060

An attacker could have accessed internal pages or data by ex-filtratin ...

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
nvd логотип
CVE-2023-49060

An attacker could have accessed internal pages or data by ex-filtrating a security key from ReaderMode via the `referrerpolicy` attribute. This vulnerability affects Firefox for iOS < 120.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад

Уязвимостей на страницу


Поделиться