Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

1281291301311321331341351361371381391402024202520262027

Недавние уязвимости Mozilla Firefox

Количество 14 608

nvd логотип

CVE-2024-10464

8 месяцев назад

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10464

8 месяцев назад

Repeated writes to history interface attributes could have been used t ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10463

8 месяцев назад

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10463

8 месяцев назад

Video frames could have been leaked between origins in some situations ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10462

8 месяцев назад

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2024-10462

8 месяцев назад

Truncation of a long URL could have allowed origin spoofing in a permi ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2024-10461

8 месяцев назад

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2024-10461

8 месяцев назад

In multipart/x-mixed-replace responses, `Content-Disposition: attachme ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2024-10460

8 месяцев назад

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-10460

8 месяцев назад

The origin of an external protocol handler prompt could have been obsc ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-10464

Repeated writes to history interface attributes could have been used to cause a Denial of Service condition in the browser. This was addressed by introducing rate-limiting to this API. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
1%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10464

Repeated writes to history interface attributes could have been used t ...

CVSS3: 6.5
1%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-10463

Video frames could have been leaked between origins in some situations. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10463

Video frames could have been leaked between origins in some situations ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-10462

Truncation of a long URL could have allowed origin spoofing in a permission prompt. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.5
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10462

Truncation of a long URL could have allowed origin spoofing in a permi ...

CVSS3: 6.5
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-10461

In multipart/x-mixed-replace responses, `Content-Disposition: attachment` in the response header was not respected and did not force a download, which could allow XSS attacks. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 6.1
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10461

In multipart/x-mixed-replace responses, `Content-Disposition: attachme ...

CVSS3: 6.1
0%
Низкий
8 месяцев назад
nvd логотип
CVE-2024-10460

The origin of an external protocol handler prompt could have been obscured using a data: URL within an `iframe`. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Thunderbird < 128.4, and Thunderbird < 132.

CVSS3: 5.3
0%
Низкий
8 месяцев назад
debian логотип
CVE-2024-10460

The origin of an external protocol handler prompt could have been obsc ...

CVSS3: 5.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу


Поделиться