Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-45416

больше 3 лет назад

Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-45415

больше 3 лет назад

When downloading an HTML file, if the title of the page was formatted ...

CVSS3: 7.8
EPSS: Низкий
nvd логотип

CVE-2022-45415

больше 3 лет назад

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2022-45413

больше 3 лет назад

Using the <code>S.browser_fallback_url parameter</code> parameter, an ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-45413

больше 3 лет назад

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-45412

больше 3 лет назад

When resolving a symlink such as <code>file:///proc/self/fd/1</code>, ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-45412

больше 3 лет назад

When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-45411

больше 3 лет назад

Cross-Site Tracing occurs when a server will echo a request back via t ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2022-45411

больше 3 лет назад

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on <code>fetch()</code> and XMLHttpRequest; however some webservers have implemented non-standard headers such as <code>X-Http-Method-Override</code> that override the HTTP method, and made this attack possible again. Thunderbird has applied the same mitigations to the use of this and similar headers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-45410

больше 3 лет назад

When a ServiceWorker intercepted a request with <code>FetchEvent</code ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-45416

Keyboard events reference strings like "KeyA" that were at fixed, known, and widely-spread addresses. Cache-based timing attacks such as Prime+Probe could have possibly figured out which keys were being pressed. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45415

When downloading an HTML file, if the title of the page was formatted ...

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45415

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45413

Using the <code>S.browser_fallback_url parameter</code> parameter, an ...

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45413

Using the <code>S.browser_fallback_url parameter</code> parameter, an attacker could redirect a user to a URL and cause SameSite=Strict cookies to be sent.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 107.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45412

When resolving a symlink such as <code>file:///proc/self/fd/1</code>, ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45412

When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45411

Cross-Site Tracing occurs when a server will echo a request back via t ...

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45411

Cross-Site Tracing occurs when a server will echo a request back via the Trace method, allowing an XSS attack to access to authorization headers and cookies inaccessible to JavaScript (such as cookies protected by HTTPOnly). To mitigate this attack, browsers placed limits on <code>fetch()</code> and XMLHttpRequest; however some webservers have implemented non-standard headers such as <code>X-Http-Method-Override</code> that override the HTTP method, and made this attack possible again. Thunderbird has applied the same mitigations to the use of this and similar headers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45410

When a ServiceWorker intercepted a request with <code>FetchEvent</code ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться