Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-22763

больше 3 лет назад

When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22762

больше 3 лет назад

Under certain circumstances, a JavaScript alert (or prompt) could have ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-22762

больше 3 лет назад

Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-22761

больше 3 лет назад

Web-accessible extension pages (pages with a moz-extension:// scheme) ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-22761

больше 3 лет назад

Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22760

больше 3 лет назад

When importing resources using Web Workers, error messages would disti ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22760

больше 3 лет назад

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22759

больше 3 лет назад

If a document created a sandboxed iframe without <code>allow-scripts</ ...

CVSS3: 9.6
EPSS: Низкий
nvd логотип

CVE-2022-22759

больше 3 лет назад

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2022-22758

больше 3 лет назад

When clicking on a tel: link, USSD codes, specified after a <code>\*</ ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-22763

When a worker is shutdown, it was possible to cause script to run late in the lifecycle, at a point after where it should not be possible. This vulnerability affects Firefox < 96, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22762

Under certain circumstances, a JavaScript alert (or prompt) could have ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22762

Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22761

Web-accessible extension pages (pages with a moz-extension:// scheme) ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22761

Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22760

When importing resources using Web Workers, error messages would disti ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22760

When importing resources using Web Workers, error messages would distinguish the difference between <code>application/javascript</code> responses and non-script responses. This could have been abused to learn information cross-origin. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22759

If a document created a sandboxed iframe without <code>allow-scripts</ ...

CVSS3: 9.6
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22759

If a document created a sandboxed iframe without <code>allow-scripts</code>, and subsequently appended an element to the iframe's document that e.g. had a JavaScript event handler - the event handler would have run despite the iframe's sandbox. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 9.6
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22758

When clicking on a tel: link, USSD codes, specified after a <code>\*</ ...

CVSS3: 8.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться