Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 668

github логотип

GHSA-683q-h46v-73wp

больше 4 лет назад

Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-4qq8-cxv5-977h

больше 4 лет назад

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-j6xp-8wg9-2gf2

больше 4 лет назад

Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w92w-fc6m-j79x

больше 4 лет назад

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-73hr-36wp-4xmc

больше 4 лет назад

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-5w2r-q893-4x6m

больше 4 лет назад

Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vhpc-6pcw-g9p4

больше 4 лет назад

Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9f9w-vwq3-c9fh

больше 4 лет назад

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x4mq-76g8-78f6

больше 4 лет назад

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-px89-65ch-24x4

больше 4 лет назад

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-683q-h46v-73wp

Unspecified vulnerability in the browser engine in Mozilla Firefox ESR 38.x before 38.8 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-4qq8-cxv5-977h

The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.

CVSS3: 5.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-j6xp-8wg9-2gf2

Race condition in the get implementation in the ServiceWorkerManager class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and application crash) via a crafted web site.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-w92w-fc6m-j79x

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

CVSS3: 8.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-73hr-36wp-4xmc

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.

CVSS3: 5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-5w2r-q893-4x6m

Heap-based buffer overflow in the stagefright::SampleTable::parseSampleCencInfo function in libstagefright in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allows remote attackers to execute arbitrary code via crafted CENC offsets that lead to mismanagement of the sizes table.

CVSS3: 8.8
4%
Низкий
больше 4 лет назад
github логотип
GHSA-vhpc-6pcw-g9p4

Mozilla Firefox before 46.0 allows remote attackers to bypass the Content Security Policy (CSP) protection mechanism via the multipart/x-mixed-replace content type.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-9f9w-vwq3-c9fh

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-x4mq-76g8-78f6

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-px89-65ch-24x4

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться