Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 668

github логотип

GHSA-g989-pp3h-prh7

больше 4 лет назад

A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-874r-f6v2-m748

больше 4 лет назад

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-ch5f-5368-9hw8

больше 4 лет назад

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-v73x-jj5r-xff3

больше 4 лет назад

A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6j32-5w3w-vrq5

больше 4 лет назад

Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-5xc2-gx42-84wf

больше 4 лет назад

Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-v3g4-2m5p-cjh4

больше 4 лет назад

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-92cf-2847-r49w

больше 4 лет назад

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xrvj-239r-5xw7

больше 4 лет назад

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-qpcp-783x-fcf2

больше 4 лет назад

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-g989-pp3h-prh7

A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-874r-f6v2-m748

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-ch5f-5368-9hw8

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.

CVSS3: 7.5
14%
Средний
больше 4 лет назад
github логотип
GHSA-v73x-jj5r-xff3

A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-6j32-5w3w-vrq5

Memory safety bugs were reported in Firefox 55. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 56.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-5xc2-gx42-84wf

Response header name interning does not have same-origin protections and these headers are stored in a global registry. This allows stored header names to be available cross-origin. This vulnerability affects Firefox < 55.

CVSS3: 7.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-v3g4-2m5p-cjh4

An integer overflow during the parsing of XML using the Expat library. This vulnerability affects Firefox < 50.

CVSS3: 9.8
5%
Низкий
больше 4 лет назад
github логотип
GHSA-92cf-2847-r49w

Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
github логотип
GHSA-xrvj-239r-5xw7

Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 5.9
2%
Низкий
больше 4 лет назад
github логотип
GHSA-qpcp-783x-fcf2

A potentially exploitable use-after-free crash during actor destruction with service workers. This issue does not affect releases earlier than Firefox 49. This vulnerability affects Firefox < 49.0.2.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться