Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-32209

около 3 лет назад

A maliciously crafted favicon could have led to an out of memory crash ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2023-32209

около 3 лет назад

A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2023-32208

около 3 лет назад

Service workers could reveal script base URL due to dynamic `import()` ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2023-32208

около 3 лет назад

Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2023-29532

около 3 лет назад

A local attacker can trick the Mozilla Maintenance Service into applyi ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2023-29532

около 3 лет назад

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2023-29531

около 3 лет назад

An attacker could have caused an out of bounds memory access using Web ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-29531

около 3 лет назад

An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-32216

около 3 лет назад

Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2023-32214

около 3 лет назад

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-32209

A maliciously crafted favicon could have led to an out of memory crash ...

CVSS3: 7.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-32209

A maliciously crafted favicon could have led to an out of memory crash. This vulnerability affects Firefox < 113.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-32208

Service workers could reveal script base URL due to dynamic `import()` ...

CVSS3: 5.3
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-32208

Service workers could reveal script base URL due to dynamic `import()`. This vulnerability affects Firefox < 113.

CVSS3: 5.3
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29532

A local attacker can trick the Mozilla Maintenance Service into applyi ...

CVSS3: 5.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29532

A local attacker can trick the Mozilla Maintenance Service into applying an unsigned update file by pointing the service at an update file on a malicious SMB server. The update file can be replaced after the signature check, before the use, because the write-lock requested by the service does not work on a SMB server. *Note: This attack requires local system access and only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 5.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29531

An attacker could have caused an out of bounds memory access using Web ...

CVSS3: 9.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29531

An attacker could have caused an out of bounds memory access using WebGL APIs, leading to memory corruption and a potentially exploitable crash. *This bug only affects Firefox and Thunderbird for macOS. Other operating systems are unaffected.* This vulnerability affects Firefox < 112, Firefox ESR < 102.10, and Thunderbird < 102.10.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-32216

Mozilla developers and community members Ronald Crane, Andrew McCreight, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 112. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 113.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2023-32214

Protocol handlers `ms-cxh` and `ms-cxh-full` could have been leveraged to trigger a denial of service. *Note: This attack only affects Windows. Other operating systems are not affected.* This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.

CVSS3: 7.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться