Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-40956

больше 3 лет назад

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2022-3266

больше 3 лет назад

An out-of-bounds read can occur when decoding H264 video. This results ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2022-3266

больше 3 лет назад

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2022-38478

больше 3 лет назад

Members the Mozilla Fuzzing Team reported memory safety bugs present i ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-38478

больше 3 лет назад

Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-38477

больше 3 лет назад

Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported m ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-38477

больше 3 лет назад

Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird < 102.2, and Firefox < 104.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-38475

больше 3 лет назад

An attacker could have written a value to the first element in a zero- ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-38475

больше 3 лет назад

An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-38474

больше 3 лет назад

A website that had permission to access the microphone could record au ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-40956

When injecting an HTML base element, some requests would ignore the CSP's base-uri settings and accept the injected element's base instead. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-3266

An out-of-bounds read can occur when decoding H264 video. This results ...

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-3266

An out-of-bounds read can occur when decoding H264 video. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 102.3, Thunderbird < 102.3, and Firefox < 105.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-38478

Members the Mozilla Fuzzing Team reported memory safety bugs present i ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-38478

Members the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103, Firefox ESR 102.1, and Firefox ESR 91.12. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-38477

Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported m ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-38477

Mozilla developer Nika Layzell and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 103 and Firefox ESR 102.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 102.2, Thunderbird < 102.2, and Firefox < 104.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-38475

An attacker could have written a value to the first element in a zero- ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-38475

An attacker could have written a value to the first element in a zero-length JavaScript array. Although the array was zero-length, the value was not written to an invalid memory address. This vulnerability affects Firefox < 104.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-38474

A website that had permission to access the microphone could record au ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться