Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2023-5176

почти 3 года назад

Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-5175

почти 3 года назад

During process shutdown, it was possible that an `ImageBitmap` was cre ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-5175

почти 3 года назад

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-5174

почти 3 года назад

If Windows failed to duplicate a handle during process creation, the s ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-5174

почти 3 года назад

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-5173

почти 3 года назад

In a non-standard configuration of Firefox, an integer overflow could ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-5173

почти 3 года назад

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-5172

почти 3 года назад

A hashtable in the Ion Engine could have been mutated while there was ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-5172

почти 3 года назад

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-5171

почти 3 года назад

During Ion compilation, a Garbage Collection could have resulted in a ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-5176

Memory safety bugs present in Firefox 117, Firefox ESR 115.2, and Thunderbird 115.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5175

During process shutdown, it was possible that an `ImageBitmap` was cre ...

CVSS3: 9.8
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5175

During process shutdown, it was possible that an `ImageBitmap` was created that would later be used after being freed from a different codepath, leading to a potentially exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5174

If Windows failed to duplicate a handle during process creation, the s ...

CVSS3: 9.8
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5174

If Windows failed to duplicate a handle during process creation, the sandbox code may have inadvertently freed a pointer twice, resulting in a use-after-free and a potentially exploitable crash. *This bug only affects Firefox on Windows when run in non-standard configurations (such as using `runas`). Other operating systems are unaffected.* This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5173

In a non-standard configuration of Firefox, an integer overflow could ...

CVSS3: 7.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5173

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5172

A hashtable in the Ion Engine could have been mutated while there was ...

CVSS3: 9.8
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-5172

A hashtable in the Ion Engine could have been mutated while there was a live interior reference, leading to a potential use-after-free and exploitable crash. This vulnerability affects Firefox < 118.

CVSS3: 9.8
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-5171

During Ion compilation, a Garbage Collection could have resulted in a ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад

Уязвимостей на страницу


Поделиться