Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 668

github логотип

GHSA-9rjc-h49g-75c4

больше 4 лет назад

Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xmc5-26p9-v4x6

больше 4 лет назад

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-cxh5-m5cc-6w2r

больше 4 лет назад

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-h94p-p746-v4fv

больше 4 лет назад

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-q432-46p9-q7g4

больше 4 лет назад

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-q77m-7m77-g2rw

больше 4 лет назад

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-83r9-7w8h-jjf7

больше 4 лет назад

A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vf32-w5gr-6vmw

больше 4 лет назад

A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-96c7-2g3r-8573

больше 4 лет назад

An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory containing matches to specifically set patterns. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-m5vj-4h2v-cf67

больше 4 лет назад

A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-9rjc-h49g-75c4

Memory safety bugs were reported in Firefox 50.0.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 50.1.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xmc5-26p9-v4x6

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-cxh5-m5cc-6w2r

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад
github логотип
GHSA-h94p-p746-v4fv

A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-q432-46p9-q7g4

A "javascript:" url loaded by a malicious page can obfuscate its location by blanking the URL displayed in the addressbar, allowing for an attacker to spoof an existing page without the malicious page's address being displayed correctly. This vulnerability affects Firefox < 52.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-q77m-7m77-g2rw

The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-83r9-7w8h-jjf7

A buffer overflow read during SVG filter color value operations, resulting in data exposure. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 7.5
5%
Низкий
больше 4 лет назад
github логотип
GHSA-vf32-w5gr-6vmw

A use-after-free vulnerability occurs during certain text input selection resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.

CVSS3: 9.8
3%
Низкий
больше 4 лет назад
github логотип
GHSA-96c7-2g3r-8573

An out of bounds read error occurs when parsing some HTTP digest authorization responses, resulting in information leakage through the reading of random memory containing matches to specifically set patterns. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 5.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-m5vj-4h2v-cf67

A segmentation fault can occur during some bidirectional layout operations. This vulnerability affects Firefox < 52 and Thunderbird < 52.

CVSS3: 9.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться