Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"
Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

1281291301311321331341351361371381391402024202520262027

Недавние уязвимости Mozilla Firefox

Количество 14 679

nvd логотип

CVE-2024-8385

10 месяцев назад

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-8385

10 месяцев назад

A difference in the handling of StructFields and ArrayTypes in WASM co ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-8384

10 месяцев назад

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2024-8384

10 месяцев назад

The JavaScript garbage collector could mis-color cross-compartment obj ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-8383

10 месяцев назад

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2024-8383

10 месяцев назад

Firefox normally asks for confirmation before asking the operating sys ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2024-8382

10 месяцев назад

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2024-8382

10 месяцев назад

Internal browser event interfaces were exposed to web content when pri ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2024-8381

10 месяцев назад

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2024-8381

10 месяцев назад

A potentially exploitable type confusion could be triggered when looki ...

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-8385

A difference in the handling of StructFields and ArrayTypes in WASM could be used to trigger an exploitable type confusion vulnerability. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Thunderbird < 128.2.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
debian логотип
CVE-2024-8385

A difference in the handling of StructFields and ArrayTypes in WASM co ...

CVSS3: 9.8
1%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-8384

The JavaScript garbage collector could mis-color cross-compartment objects if OOM conditions were detected at the right point between two passes. This could have led to memory corruption. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS3: 9.8
1%
Низкий
10 месяцев назад
debian логотип
CVE-2024-8384

The JavaScript garbage collector could mis-color cross-compartment obj ...

CVSS3: 9.8
1%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-8383

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-8383

Firefox normally asks for confirmation before asking the operating sys ...

CVSS3: 7.5
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-8382

Internal browser event interfaces were exposed to web content when privileged EventHandler listener callbacks ran for those events. Web content that tried to use those interfaces would not be able to use them with elevated privileges, but their presence would indicate certain browser features had been used, such as when a user opened the Dev Tools console. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS3: 8.8
0%
Низкий
10 месяцев назад
debian логотип
CVE-2024-8382

Internal browser event interfaces were exposed to web content when pri ...

CVSS3: 8.8
0%
Низкий
10 месяцев назад
nvd логотип
CVE-2024-8381

A potentially exploitable type confusion could be triggered when looking up a property name on an object being used as the `with` environment. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, Firefox ESR < 115.15, Thunderbird < 128.2, and Thunderbird < 115.15.

CVSS3: 9.8
16%
Средний
10 месяцев назад
debian логотип
CVE-2024-8381

A potentially exploitable type confusion could be triggered when looki ...

CVSS3: 9.8
16%
Средний
10 месяцев назад

Уязвимостей на страницу


Поделиться