Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 668

github логотип

GHSA-w6cr-qvrp-w86v

больше 4 лет назад

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-29w8-qmxg-g64x

больше 4 лет назад

The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-xq8c-wgh5-f4w9

больше 4 лет назад

Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-q2gv-w495-jmxw

больше 4 лет назад

Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-72cx-7rj4-3mpc

больше 4 лет назад

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cx3x-8cg7-v23q

больше 4 лет назад

Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-6w2j-4h6c-6wqg

больше 4 лет назад

Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-gvh4-3r7j-cv8q

больше 4 лет назад

Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-7w2r-5rh4-3w9j

больше 4 лет назад

Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.

EPSS: Низкий
github логотип

GHSA-c3x3-j36w-9jmm

больше 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-w6cr-qvrp-w86v

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
0%
Низкий
больше 4 лет назад
github логотип
GHSA-29w8-qmxg-g64x

The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xq8c-wgh5-f4w9

Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-q2gv-w495-jmxw

Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

CVSS3: 6.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-72cx-7rj4-3mpc

The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-cx3x-8cg7-v23q

Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-6w2j-4h6c-6wqg

Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.

CVSS3: 5.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-gvh4-3r7j-cv8q

Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-7w2r-5rh4-3w9j

Mozilla Firefox before 37.0 on OS X does not ensure that the cursor is visible, which allows remote attackers to conduct clickjacking attacks via a Flash object in conjunction with DIV elements associated with layered presentation, and crafted JavaScript code that interacts with an IMG element.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-c3x3-j36w-9jmm

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

5%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться