Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 337

nvd логотип

CVE-2022-22748

больше 3 лет назад

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22747

больше 3 лет назад

After accepting an untrusted certificate, handling an empty pkcs7 sequ ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22747

больше 3 лет назад

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22746

больше 3 лет назад

A race condition could have allowed bypassing the fullscreen notificat ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2022-22746

больше 3 лет назад

A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2022-22745

больше 3 лет назад

Securitypolicyviolation events could have leaked cross-origin informat ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22745

больше 3 лет назад

Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22744

больше 3 лет назад

The constructed curl command from the "Copy as curl" feature in DevToo ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2022-22744

больше 3 лет назад

The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2022-22743

больше 3 лет назад

When navigating from inside an iframe while requesting fullscreen acce ...

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2022-22748

Malicious websites could have confused Firefox into showing the wrong origin when asking to launch a program and handling an external URL protocol. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22747

After accepting an untrusted certificate, handling an empty pkcs7 sequ ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22747

After accepting an untrusted certificate, handling an empty pkcs7 sequence as part of the certificate data could have lead to a crash. This crash is believed to be unexploitable. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22746

A race condition could have allowed bypassing the fullscreen notificat ...

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22746

A race condition could have allowed bypassing the fullscreen notification which could have lead to a fullscreen window spoof being unnoticed.<br>*This bug only affects Firefox for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 5.9
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22745

Securitypolicyviolation events could have leaked cross-origin informat ...

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22745

Securitypolicyviolation events could have leaked cross-origin information for frame-ancestors violations. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22744

The constructed curl command from the "Copy as curl" feature in DevToo ...

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-22744

The constructed curl command from the "Copy as curl" feature in DevTools was not properly escaped for PowerShell. This could have lead to command injection if pasted into a Powershell prompt.<br>*This bug only affects Thunderbird for Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 91.5, Firefox < 96, and Thunderbird < 91.5.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-22743

When navigating from inside an iframe while requesting fullscreen acce ...

CVSS3: 4.3
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу


Поделиться