Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-29543

около 3 лет назад

An attacker could have caused memory corruption and a potentially expl ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-29543

около 3 лет назад

An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-29541

около 3 лет назад

Firefox did not properly handle downloads of files ending in <code>.de ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-29541

около 3 лет назад

Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-29540

около 3 лет назад

Using a redirect embedded into <code>sourceMappingUrls</code> could al ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2023-29540

около 3 лет назад

Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2023-29539

около 3 лет назад

When handling the filename directive in the Content-Disposition header ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-29539

около 3 лет назад

When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-29538

около 3 лет назад

Under specific circumstances a WebExtension may have received a <code> ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2023-29538

около 3 лет назад

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-29543

An attacker could have caused memory corruption and a potentially expl ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29543

An attacker could have caused memory corruption and a potentially exploitable use-after-free of a pointer in a global object's debugger vector. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29541

Firefox did not properly handle downloads of files ending in <code>.de ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29541

Firefox did not properly handle downloads of files ending in <code>.desktop</code>, which can be interpreted to run attacker-controlled commands. <br>*This bug only affects Firefox for Linux on certain Distributions. Other operating systems are unaffected, and Mozilla is unable to enumerate all affected Linux Distributions.*. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29540

Using a redirect embedded into <code>sourceMappingUrls</code> could al ...

CVSS3: 6.1
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29540

Using a redirect embedded into <code>sourceMappingUrls</code> could allow for navigation to external protocol links in sandboxed iframes without <code>allow-top-navigation-to-custom-protocols</code>. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29539

When handling the filename directive in the Content-Disposition header ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29539

When handling the filename directive in the Content-Disposition header, the filename would be truncated if the filename contained a NULL character. This could have led to reflected file download attacks potentially tricking users to install malware. This vulnerability affects Firefox < 112, Focus for Android < 112, Firefox ESR < 102.10, Firefox for Android < 112, and Thunderbird < 102.10.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-29538

Under specific circumstances a WebExtension may have received a <code> ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-29538

Under specific circumstances a WebExtension may have received a <code>jar:file:///</code> URI instead of a <code>moz-extension:///</code> URI during a load request. This leaked directory paths on the user's machine. This vulnerability affects Firefox for Android < 112, Firefox < 112, and Focus for Android < 112.

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться