Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-34480

больше 3 лет назад

Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-34479

больше 3 лет назад

A malicious website that could create a popup could have resized the p ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-34479

больше 3 лет назад

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-34478

больше 3 лет назад

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</co ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-34478

больше 3 лет назад

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.<br>*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-34477

больше 3 лет назад

The MediaError message property should be consistent to avoid leaking ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-34477

больше 3 лет назад

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2022-34476

больше 3 лет назад

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP cou ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-34476

больше 3 лет назад

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-34475

больше 3 лет назад

SVG <code>&lt;use&gt;</code> tags that referenced a same-origin docume ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-34480

Within the <code>lg_init()</code> function, if several allocations succeed but then one fails, an uninitialized pointer would have been freed despite never being allocated. This vulnerability affects Firefox < 102.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-34479

A malicious website that could create a popup could have resized the p ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-34479

A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-34478

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</co ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-34478

The <code>ms-msdt</code>, <code>search</code>, and <code>search-ms</code> protocols deliver content to Microsoft applications, bypassing the browser, when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild (although we know of none exploited through Thunderbird), so in this release Thunderbird has blocked these protocols from prompting the user to open them.<br>*This bug only affects Thunderbird on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 102, Firefox ESR < 91.11, Thunderbird < 102, and Thunderbird < 91.11.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-34477

The MediaError message property should be consistent to avoid leaking ...

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-34477

The MediaError message property should be consistent to avoid leaking information about cross-origin resources; however for a same-site cross-origin resource, the message could have leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 102.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-34476

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP cou ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-34476

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-34475

SVG <code>&lt;use&gt;</code> tags that referenced a same-origin docume ...

CVSS3: 6.1
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться