Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-31741

больше 3 лет назад

A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-31740

больше 3 лет назад

On arm64, WASM code could have resulted in incorrect assembly generati ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-31740

больше 3 лет назад

On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-31739

больше 3 лет назад

When downloading files on Windows, the % character was not escaped, wh ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-31739

больше 3 лет назад

When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-31738

больше 3 лет назад

When exiting fullscreen mode, an iframe could have confused the browse ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-31738

больше 3 лет назад

When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-31737

больше 3 лет назад

A malicious webpage could have caused an out-of-bounds write in WebGL, ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2022-31737

больше 3 лет назад

A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2022-31736

больше 3 лет назад

A malicious website could have learned the size of a cross-origin reso ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-31741

A crafted CMS message could have been processed incorrectly, leading to an invalid memory read, and potentially further memory corruption. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31740

On arm64, WASM code could have resulted in incorrect assembly generati ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31740

On arm64, WASM code could have resulted in incorrect assembly generation leading to a register allocation problem, and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31739

When downloading files on Windows, the % character was not escaped, wh ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31739

When downloading files on Windows, the % character was not escaped, which could have lead to a download incorrectly being saved to attacker-influenced paths that used variables such as %HOMEPATH% or %APPDATA%.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31738

When exiting fullscreen mode, an iframe could have confused the browse ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31738

When exiting fullscreen mode, an iframe could have confused the browser about the current state of fullscreen, resulting in potential user confusion or spoofing attacks. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31737

A malicious webpage could have caused an out-of-bounds write in WebGL, ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-31737

A malicious webpage could have caused an out-of-bounds write in WebGL, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 91.10, Firefox < 101, and Firefox ESR < 91.10.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-31736

A malicious website could have learned the size of a cross-origin reso ...

CVSS3: 9.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться