Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2023-29545

около 3 лет назад

Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-29542

около 3 лет назад

A newline in a filename could have been used to bypass the file extens ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-29542

около 3 лет назад

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-29534

около 3 лет назад

Different techniques existed to obscure the fullscreen notification in ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2023-29534

около 3 лет назад

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2023-25747

около 3 лет назад

A potential use-after-free in libaudio was fixed by disabling the AAud ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-25747

около 3 лет назад

A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-25736

около 3 лет назад

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have l ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-25736

около 3 лет назад

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-25733

около 3 лет назад

The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being ver ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-29545

Similar to CVE-2023-28163, this time when choosing 'Save Link As', suggested filenames containing environment variable names would have resolved those in the context of the current user. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29542

A newline in a filename could have been used to bypass the file extens ...

CVSS3: 9.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29542

A newline in a filename could have been used to bypass the file extension security mechanisms that replace malicious file extensions such as .lnk with .download. This could have led to accidental execution of malicious code. *This bug only affects Firefox and Thunderbird on Windows. Other versions of Firefox and Thunderbird are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29534

Different techniques existed to obscure the fullscreen notification in ...

CVSS3: 9.1
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29534

Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.

CVSS3: 9.1
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25747

A potential use-after-free in libaudio was fixed by disabling the AAud ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25747

A potential use-after-free in libaudio was fixed by disabling the AAudio backend when running on Android API below version 30. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 110.1.0.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25736

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have l ...

CVSS3: 9.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25736

An invalid downcast from `nsHTMLDocument` to `nsIContent` could have lead to undefined behavior. This vulnerability affects Firefox < 110.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25733

The return value from `gfx::SourceSurfaceSkia::Map()` wasn't being ver ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться