Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-45410

больше 3 лет назад

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-45409

больше 3 лет назад

The garbage collector could have been aborted in several states and zo ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-45409

больше 3 лет назад

The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-45408

больше 3 лет назад

Through a series of popups that reuse windowName, an attacker can caus ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-45408

больше 3 лет назад

Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-45407

больше 3 лет назад

If an attacker loaded a font using <code>FontFace()</code> on a backgr ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-45407

больше 3 лет назад

If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-45406

больше 3 лет назад

If an out-of-memory condition occurred when creating a JavaScript glob ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-45406

больше 3 лет назад

If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-45405

больше 3 лет назад

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-45410

When a ServiceWorker intercepted a request with <code>FetchEvent</code>, the origin of the request was lost after the ServiceWorker took ownership of it. This had the effect of negating SameSite cookie protections. This was addressed in the spec and then in browsers. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45409

The garbage collector could have been aborted in several states and zo ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45409

The garbage collector could have been aborted in several states and zones and <code>GCRuntime::finishCollection</code> may not have been called, leading to a use-after-free and potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45408

Through a series of popups that reuse windowName, an attacker can caus ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45408

Through a series of popups that reuse windowName, an attacker can cause a window to go fullscreen without the user seeing the notification prompt, resulting in potential user confusion or spoofing attacks. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45407

If an attacker loaded a font using <code>FontFace()</code> on a backgr ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45407

If an attacker loaded a font using <code>FontFace()</code> on a background worker, a use-after-free could have occurred, leading to a potentially exploitable crash. This vulnerability affects Firefox < 107.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45406

If an out-of-memory condition occurred when creating a JavaScript glob ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-45406

If an out-of-memory condition occurred when creating a JavaScript global, a JavaScript realm may be deleted while references to it lived on in a BaseShape. This could lead to a use-after-free causing a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-45405

Freeing arbitrary <code>nsIInputStream</code>'s on a different thread ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться