Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-25735

около 3 лет назад

Cross-compartment wrappers wrapping a scripted proxy could have caused ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25735

около 3 лет назад

Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25734

около 3 лет назад

After downloading a Windows <code>.url</code> shortcut from the local ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2023-25734

около 3 лет назад

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2023-25732

около 3 лет назад

When encoding data from an <code>inputStream</code> in <code>xpcom</co ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25732

около 3 лет назад

When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25731

около 3 лет назад

Due to URL previews in the network panel of developer tools improperly ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2023-25731

около 3 лет назад

Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2023-25730

около 3 лет назад

A background script invoking <code>requestFullscreen</code> and then b ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2023-25730

около 3 лет назад

A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-25735

Cross-compartment wrappers wrapping a scripted proxy could have caused ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25735

Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main compartment resulting in a use-after-free after unwrapping the proxy. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25734

After downloading a Windows <code>.url</code> shortcut from the local ...

CVSS3: 8.1
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25734

After downloading a Windows <code>.url</code> shortcut from the local filesystem, an attacker could supply a remote path that would lead to unexpected network requests from the operating system. This also had the potential to leak NTLM credentials to the resource.<br>*This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.1
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25732

When encoding data from an <code>inputStream</code> in <code>xpcom</co ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25732

When encoding data from an <code>inputStream</code> in <code>xpcom</code> the size of the input being encoded was not correctly calculated potentially leading to an out of bounds memory write. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25731

Due to URL previews in the network panel of developer tools improperly ...

CVSS3: 8.8
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25731

Due to URL previews in the network panel of developer tools improperly storing URLs, query parameters could potentially be used to overwrite global objects in privileged code. This vulnerability affects Firefox < 110.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-25730

A background script invoking <code>requestFullscreen</code> and then b ...

CVSS3: 5.4
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-25730

A background script invoking <code>requestFullscreen</code> and then blocking the main thread could force the browser into fullscreen mode indefinitely, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox < 110, Thunderbird < 102.8, and Firefox ESR < 102.8.

CVSS3: 5.4
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться