Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-31746

больше 3 лет назад

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-31745

больше 3 лет назад

If array shift operations are not used, the Garbage Collector may have ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-31745

больше 3 лет назад

If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-31744

больше 3 лет назад

An attacker could have injected CSS into stylesheets accessible via in ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-31744

больше 3 лет назад

An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-31743

больше 3 лет назад

Firefox's HTML parser did not correctly interpret HTML comment tags, r ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-31743

больше 3 лет назад

Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-31742

больше 3 лет назад

An attacker could have exploited a timing attack by sending a large nu ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-31742

больше 3 лет назад

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-31741

больше 3 лет назад

A crafted CMS message could have been processed incorrectly, leading t ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-31746

Internal URLs are protected by a secret UUID key, which could have been leaked to web page through the Referrer header. This vulnerability affects Firefox for iOS < 102.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31745

If array shift operations are not used, the Garbage Collector may have ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31745

If array shift operations are not used, the Garbage Collector may have become confused about valid objects. This vulnerability affects Firefox < 101.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31744

An attacker could have injected CSS into stylesheets accessible via in ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31744

An attacker could have injected CSS into stylesheets accessible via internal URIs, such as resource:, and in doing so bypass a page's Content Security Policy. This vulnerability affects Firefox ESR < 91.11, Thunderbird < 102, Thunderbird < 91.11, and Firefox < 101.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31743

Firefox's HTML parser did not correctly interpret HTML comment tags, r ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31743

Firefox's HTML parser did not correctly interpret HTML comment tags, resulting in an incongruity with other browsers. This could have been used to escape HTML comments on pages that put user-controlled data in them. This vulnerability affects Firefox < 101.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31742

An attacker could have exploited a timing attack by sending a large nu ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31742

An attacker could have exploited a timing attack by sending a large number of allowCredential entries and detecting the difference between invalid key handles and cross-origin key handles. This could have led to cross-origin account linking in violation of WebAuthn goals. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31741

A crafted CMS message could have been processed incorrectly, leading t ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться