Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-22758

больше 3 лет назад

When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22757

больше 3 лет назад

Remote Agent, used in WebDriver, did not validate the Host or Origin h ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22757

больше 3 лет назад

Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22756

больше 3 лет назад

If a user was convinced to drag and drop an image to their desktop or ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-22756

больше 3 лет назад

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22755

больше 3 лет назад

By using XSL Transforms, a malicious webserver could have served a use ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-22755

больше 3 лет назад

By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22754

больше 3 лет назад

If a user installed an extension of a particular type, the extension c ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22754

больше 3 лет назад

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22753

больше 3 лет назад

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) S ...

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-22758

When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22757

Remote Agent, used in WebDriver, did not validate the Host or Origin h ...

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22757

Remote Agent, used in WebDriver, did not validate the Host or Origin headers. This could have allowed websites to connect back locally to the user's browser to control it. <br>*This bug only affected Firefox when WebDriver was enabled, which is not the default configuration.*. This vulnerability affects Firefox < 97.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22756

If a user was convinced to drag and drop an image to their desktop or ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22756

If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22755

By using XSL Transforms, a malicious webserver could have served a use ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22755

By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22754

If a user installed an extension of a particular type, the extension c ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22754

If a user installed an extension of a particular type, the extension could have auto-updated itself and while doing so, bypass the prompt which grants the new version the new requested permissions. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22753

A Time-of-Check Time-of-Use bug existed in the Maintenance (Updater) S ...

CVSS3: 7.1
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться