Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

github логотип

GHSA-p5f8-m753-hvgf

больше 3 лет назад

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-qh9q-rjpp-hqc3

больше 3 лет назад

A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-h295-679q-mhm8

больше 3 лет назад

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-46885

больше 3 лет назад

Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzin ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-46885

больше 3 лет назад

Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-46883

больше 3 лет назад

Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight a ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-46883

больше 3 лет назад

Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.<br />*Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original release of Firefox 107. This vulnerability affects Firefox < 107.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-46882

больше 3 лет назад

A use-after-free in WebGL extensions could have led to a potentially e ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-46882

больше 3 лет назад

A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-46881

больше 3 лет назад

An optimization in WebGL was incorrect in some cases, and could have l ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-p5f8-m753-hvgf

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-qh9q-rjpp-hqc3

A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-h295-679q-mhm8

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46885

Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzin ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-46885

Mozilla developers Timothy Nikkel, Ashley Hale, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 105. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 106.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46883

Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight a ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-46883

Mozilla developers Gabriele Svelto, Yulia Startsev, Andrew McCreight and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 106. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.<br />*Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original release of Firefox 107. This vulnerability affects Firefox < 107.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46882

A use-after-free in WebGL extensions could have led to a potentially e ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-46882

A use-after-free in WebGL extensions could have led to a potentially exploitable crash. This vulnerability affects Firefox < 107, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46881

An optimization in WebGL was incorrect in some cases, and could have l ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться