Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-4580

почти 3 года назад

Push notifications stored on disk in private browsing mode were not be ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-4580

почти 3 года назад

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-4579

почти 3 года назад

Search queries in the default search engine could appear to have been ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2023-4579

почти 3 года назад

Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.

CVSS3: 3.1
EPSS: Низкий
debian логотип

CVE-2023-4578

почти 3 года назад

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been se ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-4578

почти 3 года назад

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-4577

почти 3 года назад

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-4577

почти 3 года назад

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-4576

почти 3 года назад

On Windows, an integer overflow could occur in `RecordedSourceSurfaceC ...

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2023-4576

почти 3 года назад

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

CVSS3: 8.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-4580

Push notifications stored on disk in private browsing mode were not be ...

CVSS3: 6.5
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4580

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-4579

Search queries in the default search engine could appear to have been ...

CVSS3: 3.1
0%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4579

Search queries in the default search engine could appear to have been the currently navigated URL if the search query itself was a well formed URL. This could have led to a site spoofing another if it had been maliciously set as the default search engine. This vulnerability affects Firefox < 117.

CVSS3: 3.1
0%
Низкий
почти 3 года назад
debian логотип
CVE-2023-4578

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been se ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4578

When calling `JS::CheckRegExpSyntax` a Syntax Error could have been set which would end in calling `convertToRuntimeErrorAndClear`. A path in the function could attempt to allocate memory when none is available which would have caused a newly created Out of Memory exception to be mishandled as a Syntax Error. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-4577

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it ...

CVSS3: 6.5
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4577

When `UpdateRegExpStatics` attempted to access `initialStringHeap` it could already have been garbage collected prior to entering the function, which could potentially have led to an exploitable crash. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.

CVSS3: 6.5
1%
Низкий
почти 3 года назад
debian логотип
CVE-2023-4576

On Windows, an integer overflow could occur in `RecordedSourceSurfaceC ...

CVSS3: 8.6
1%
Низкий
почти 3 года назад
nvd логотип
CVE-2023-4576

On Windows, an integer overflow could occur in `RecordedSourceSurfaceCreation` which resulted in a heap buffer overflow potentially leaking sensitive data that could have led to a sandbox escape. *This bug only affects Firefox on Windows. Other operating systems are unaffected.* This vulnerability affects Firefox < 117, Firefox ESR < 102.15, Firefox ESR < 115.2, Thunderbird < 102.15, and Thunderbird < 115.2.

CVSS3: 8.6
1%
Низкий
почти 3 года назад

Уязвимостей на страницу


Поделиться