Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-46875

больше 3 лет назад

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-46874

больше 3 лет назад

A file with a long filename could have had its filename truncated to r ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-46874

больше 3 лет назад

A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-46873

больше 3 лет назад

Because Firefox did not implement the <code>unsafe-hashes</code> CSP d ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-46873

больше 3 лет назад

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-46872

больше 3 лет назад

An attacker who compromised a content process could have partially esc ...

CVSS3: 8.6
EPSS: Низкий
nvd логотип

CVE-2022-46872

больше 3 лет назад

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.6
EPSS: Низкий
debian логотип

CVE-2022-46871

больше 3 лет назад

An out of date library (libusrsctp) contained vulnerabilities that cou ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-46871

больше 3 лет назад

An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-45421

больше 3 лет назад

Mozilla developers Andrew McCreight and Gabriele Svelto reported memor ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-46875

The executable file warning was not presented when downloading .atloc and .ftploc files, which can run commands on a user's computer. <br>*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46874

A file with a long filename could have had its filename truncated to r ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-46874

A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This issue was originally included in the advisories for Thunderbird 102.6, but a patch (specific to Thunderbird) was omitted, resulting in it actually being fixed in Thunderbird 102.6.1. This vulnerability affects Firefox < 108, Thunderbird < 102.6.1, Thunderbird < 102.6, and Firefox ESR < 102.6.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46873

Because Firefox did not implement the <code>unsafe-hashes</code> CSP d ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-46873

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46872

An attacker who compromised a content process could have partially esc ...

CVSS3: 8.6
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-46872

An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.

CVSS3: 8.6
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-46871

An out of date library (libusrsctp) contained vulnerabilities that cou ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-46871

An out of date library (libusrsctp) contained vulnerabilities that could potentially be exploited. This vulnerability affects Firefox < 108.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45421

Mozilla developers Andrew McCreight and Gabriele Svelto reported memor ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться