Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-25741

около 3 лет назад

When dragging and dropping an image cross-origin, the image's size cou ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-25741

около 3 лет назад

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-25740

около 3 лет назад

After downloading a Windows <code>.scf</code> script from the local fi ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25740

около 3 лет назад

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25739

около 3 лет назад

Module load requests that failed were not being checked as to whether ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25739

около 3 лет назад

Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25738

около 3 лет назад

Members of the <code>DEVMODEW</code> struct set by the printer device ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-25738

около 3 лет назад

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-25737

около 3 лет назад

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</ ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25737

около 3 лет назад

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-25741

When dragging and dropping an image cross-origin, the image's size cou ...

CVSS3: 6.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25741

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25740

After downloading a Windows <code>.scf</code> script from the local fi ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25740

After downloading a Windows <code>.scf</code> script from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25739

Module load requests that failed were not being checked as to whether ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25739

Module load requests that failed were not being checked as to whether or not they were cancelled causing a use-after-free in <code>ScriptLoadContext</code>. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25738

Members of the <code>DEVMODEW</code> struct set by the printer device ...

CVSS3: 6.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25738

Members of the <code>DEVMODEW</code> struct set by the printer device driver weren't being validated and could have resulted in invalid values which in turn would cause the browser to attempt out of bounds access to related variables.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25737

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</ ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25737

An invalid downcast from <code>nsTextNode</code> to <code>SVGElement</code> could have lead to undefined behavior. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться