Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

github логотип

GHSA-52cj-9wxr-xfhp

почти 3 года назад

A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-p85h-gwrr-6mrj

почти 3 года назад

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-5c37-6j7c-hr7x

почти 3 года назад

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3qmg-867g-8xrq

почти 3 года назад

During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-3cw5-74j7-6q4r

почти 3 года назад

Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a server-supplied Vary header. This vulnerability affects Firefox < 119.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-5758

почти 3 года назад

When opening a page in reader mode, the redirect URL could have caused ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-5758

почти 3 года назад

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-5732

почти 3 года назад

An attacker could have created a malicious link using bidirectional ch ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-5732

почти 3 года назад

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-5731

почти 3 года назад

Memory safety bugs present in Firefox 118. Some of these bugs showed e ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-52cj-9wxr-xfhp

A malicious web site can enter fullscreen mode while simultaneously triggering a WebAuthn prompt. This could have obscured the fullscreen notification and could have been leveraged in a spoofing attack. This vulnerability affects Firefox < 119.

CVSS3: 4.3
1%
Низкий
почти 3 года назад
github логотип
GHSA-p85h-gwrr-6mrj

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-5c37-6j7c-hr7x

The executable file warning was not presented when downloading .msix, .msixbundle, .appx, and .appxbundle files, which can run commands on a user's computer. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3qmg-867g-8xrq

During garbage collection extra operations were performed on a object that should not be. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 119, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-3cw5-74j7-6q4r

Using iterative requests an attacker was able to learn the size of an opaque response, as well as the contents of a server-supplied Vary header. This vulnerability affects Firefox < 119.

CVSS3: 5.3
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5758

When opening a page in reader mode, the redirect URL could have caused ...

CVSS3: 6.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5758

When opening a page in reader mode, the redirect URL could have caused attacker-controlled script to execute in a reflected Cross-Site Scripting (XSS) attack. This vulnerability affects Firefox for iOS < 119.

CVSS3: 6.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5732

An attacker could have created a malicious link using bidirectional ch ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5732

An attacker could have created a malicious link using bidirectional characters to spoof the location in the address bar when visited. This vulnerability affects Firefox < 117, Firefox ESR < 115.4, and Thunderbird < 115.4.1.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5731

Memory safety bugs present in Firefox 118. Some of these bugs showed e ...

CVSS3: 9.8
1%
Низкий
почти 3 года назад

Уязвимостей на страницу


Поделиться