Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 668

github логотип

GHSA-583h-cvpv-jvr9

больше 4 лет назад

Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w8wv-29f2-fhc6

больше 4 лет назад

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-hw5m-xj65-6qh5

больше 4 лет назад

Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-x9jq-pqmx-gf7r

больше 4 лет назад

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-762q-83qx-7jc3

больше 4 лет назад

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-7fwr-rxv9-jvxf

больше 4 лет назад

Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.

EPSS: Низкий
github логотип

GHSA-r97x-58x3-7qgg

больше 4 лет назад

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-ghc9-5whm-hrvq

больше 4 лет назад

The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecified vectors, related to an "off-by-three" error.

EPSS: Низкий
github логотип

GHSA-v8rx-7xrc-grgm

больше 4 лет назад

WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization traffic directly and is limited to the process of user login to the website and the data displayed to the user once logged in. This vulnerability affects Firefox < 60.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xf5w-2jf5-86c8

больше 4 лет назад

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-583h-cvpv-jvr9

Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-w8wv-29f2-fhc6

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

CVSS3: 8.1
3%
Низкий
больше 4 лет назад
github логотип
GHSA-hw5m-xj65-6qh5

Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-x9jq-pqmx-gf7r

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
github логотип
GHSA-762q-83qx-7jc3

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Pass::readPass function.

CVSS3: 8.1
1%
Низкий
больше 4 лет назад
github логотип
GHSA-7fwr-rxv9-jvxf

Use-after-free vulnerability in the mozilla::dom::IndexedDB::IDBObjectStore::CreateIndex function in Mozilla Firefox before 36.0, Firefox ESR 31.x before 31.5, and Thunderbird before 31.5 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via crafted content that is improperly handled during IndexedDB index creation.

4%
Низкий
больше 4 лет назад
github логотип
GHSA-r97x-58x3-7qgg

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.

CVSS3: 8.1
2%
Низкий
больше 4 лет назад
github логотип
GHSA-ghc9-5whm-hrvq

The Program::getActiveUniformMaxLength function in libGLESv2/Program.cpp in libGLESv2.dll in the WebGLES library in Almost Native Graphics Layer Engine (ANGLE), as used in Mozilla Firefox 4.x before 4.0.1 on Windows and in the GPU process in Google Chrome before 10.0.648.205 on Windows, allows remote attackers to execute arbitrary code via unspecified vectors, related to an "off-by-three" error.

3%
Низкий
больше 4 лет назад
github логотип
GHSA-v8rx-7xrc-grgm

WebExtensions with the appropriate permissions can attach content scripts to Mozilla sites such as accounts.firefox.com and listen to network traffic to the site through the "webRequest" API. For example, this allows for the interception of username and an encrypted password during login to Firefox Accounts. This issue does not expose synchronization traffic directly and is limited to the process of user login to the website and the data displayed to the user once logged in. This vulnerability affects Firefox < 60.

CVSS3: 6.5
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xf5w-2jf5-86c8

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

CVSS3: 7.5
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться