Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-38474

больше 3 лет назад

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-38473

больше 3 лет назад

A cross-origin iframe referencing an XSLT document would inherit the p ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-38473

больше 3 лет назад

A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-38472

больше 3 лет назад

An attacker could have abused XSLT error handling to associate attacke ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-38472

больше 3 лет назад

An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-36320

больше 3 лет назад

Mozilla developers and the Mozilla Fuzzing Team reported memory safety ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-36320

больше 3 лет назад

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-36319

больше 3 лет назад

When combining CSS properties for overflow and transform, the mouse cu ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-36319

больше 3 лет назад

When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-36318

больше 3 лет назад

When visiting directory listings for `chrome://` URLs as source text, ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-38474

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-38473

A cross-origin iframe referencing an XSLT document would inherit the p ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-38473

A cross-origin iframe referencing an XSLT document would inherit the parent domain's permissions (such as microphone or camera access). This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-38472

An attacker could have abused XSLT error handling to associate attacke ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-38472

An attacker could have abused XSLT error handling to associate attacker-controlled content with another origin which was displayed in the address bar. This could have been used to fool the user into submitting data intended for the spoofed origin. This vulnerability affects Thunderbird < 102.2, Thunderbird < 91.13, Firefox ESR < 91.13, Firefox ESR < 102.2, and Firefox < 104.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-36320

Mozilla developers and the Mozilla Fuzzing Team reported memory safety ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-36320

Mozilla developers and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 102. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 103.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-36319

When combining CSS properties for overflow and transform, the mouse cu ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-36319

When combining CSS properties for overflow and transform, the mouse cursor could interact with different coordinates than displayed. This vulnerability affects Firefox ESR < 102.1, Firefox ESR < 91.12, Firefox < 103, Thunderbird < 102.1, and Thunderbird < 91.12.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-36318

When visiting directory listings for `chrome://` URLs as source text, ...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться