Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-26384

больше 3 лет назад

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2022-26383

больше 3 лет назад

When resizing a popup after requesting fullscreen access, the popup wo ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-26383

больше 3 лет назад

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-26382

больше 3 лет назад

While the text displayed in Autofill tooltips cannot be directly read ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-26382

больше 3 лет назад

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-26381

больше 3 лет назад

An attacker could have caused a use-after-free by forcing a text reflo ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-26381

больше 3 лет назад

An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22764

больше 3 лет назад

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported m ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-22764

больше 3 лет назад

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22763

больше 3 лет назад

When a worker is shutdown, it was possible to cause script to run late ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-26384

If an attacker could control the contents of an iframe sandboxed with <code>allow-popups</code> but not <code>allow-scripts</code>, they were able to craft a link that, when clicked, would lead to JavaScript execution in violation of the sandbox. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 9.6
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-26383

When resizing a popup after requesting fullscreen access, the popup wo ...

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-26383

When resizing a popup after requesting fullscreen access, the popup would not display the fullscreen notification. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-26382

While the text displayed in Autofill tooltips cannot be directly read ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-26382

While the text displayed in Autofill tooltips cannot be directly read by JavaScript, the text was rendered using page fonts. Side-channel attacks on the text by using specially crafted fonts could have lead to this text being inferred by the webpage. This vulnerability affects Firefox < 98.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-26381

An attacker could have caused a use-after-free by forcing a text reflo ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-26381

An attacker could have caused a use-after-free by forcing a text reflow in an SVG object leading to a potentially exploitable crash. This vulnerability affects Firefox < 98, Firefox ESR < 91.7, and Thunderbird < 91.7.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22764

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported m ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22764

Mozilla developers Paul Adenot and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 96 and Firefox ESR 91.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22763

When a worker is shutdown, it was possible to cause script to run late ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться