Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

debian логотип

CVE-2023-23603

около 3 лет назад

Regular expressions used to filter out forbidden properties and values ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23603

около 3 лет назад

Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23602

около 3 лет назад

A mishandled security check when creating a WebSocket in a WebWorker c ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23602

около 3 лет назад

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23601

около 3 лет назад

Navigations were being allowed when dragging a URL from a cross-origin ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23601

около 3 лет назад

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23600

около 3 лет назад

Per origin notification permissions were being stored in a way that di ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23600

около 3 лет назад

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2023-23599

около 3 лет назад

When copying a network request from the developer tools panel as a cur ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2023-23599

около 3 лет назад

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2023-23603

Regular expressions used to filter out forbidden properties and values ...

CVSS3: 6.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-23603

Regular expressions used to filter out forbidden properties and values from style directives in calls to `console.log` weren't accounting for external URLs. Data could then be potentially exfiltrated from the browser. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-23602

A mishandled security check when creating a WebSocket in a WebWorker c ...

CVSS3: 6.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-23602

A mishandled security check when creating a WebSocket in a WebWorker caused the Content Security Policy connect-src header to be ignored. This could lead to connections to restricted origins from inside WebWorkers. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2023-23601

Navigations were being allowed when dragging a URL from a cross-origin ...

CVSS3: 6.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-23601

Navigations were being allowed when dragging a URL from a cross-origin iframe into the same tab which could lead to website spoofing attacks This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-23600

Per origin notification permissions were being stored in a way that di ...

CVSS3: 6.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-23600

Per origin notification permissions were being stored in a way that didn't take into account what browsing context the permission was granted in. This lead to the possibility of notifications to be displayed during different browsing sessions. *This bug only affects Firefox for Android. Other operating systems are unaffected.* This vulnerability affects Firefox < 109.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2023-23599

When copying a network request from the developer tools panel as a cur ...

CVSS3: 6.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2023-23599

When copying a network request from the developer tools panel as a curl command the output was not being properly sanitized and could allow arbitrary commands to be hidden within. This vulnerability affects Firefox < 109, Firefox ESR < 102.7, and Thunderbird < 102.7.

CVSS3: 6.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться