Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

github логотип

GHSA-h29q-7v28-gprh

больше 4 лет назад

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

EPSS: Низкий
github логотип

GHSA-5253-q8v4-qcg9

больше 4 лет назад

Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.

EPSS: Низкий
github логотип

GHSA-xwxc-wc23-rvj5

больше 4 лет назад

Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.

EPSS: Низкий
github логотип

GHSA-c2mm-7gpv-8xqx

больше 4 лет назад

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

EPSS: Низкий
github логотип

GHSA-94wq-jwp8-mvj5

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."

EPSS: Низкий
github логотип

GHSA-pcv9-8f4w-qrgp

больше 4 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

EPSS: Низкий
github логотип

GHSA-j282-cmxq-gm6v

больше 4 лет назад

Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header

EPSS: Низкий
github логотип

GHSA-jpfq-gv6p-4pv8

больше 4 лет назад

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-wg6h-56g7-mfvv

больше 4 лет назад

Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets

EPSS: Низкий
github логотип

GHSA-7c9h-gj9v-x83c

больше 4 лет назад

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-h29q-7v28-gprh

The cert_TestHostName function in Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, only checks the hostname portion of a certificate when the hostname portion of the URI is not a fully qualified domain name (FQDN), which allows remote attackers to spoof trusted certificates.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-5253-q8v4-qcg9

Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitrary programs via a URI referencing the shell: protocol.

5%
Низкий
больше 4 лет назад
github логотип
GHSA-xwxc-wc23-rvj5

Netscape Navigator 7.0.2 and Mozilla allows remote attackers to access cookie information in a different domain via an HTTP request for a domain with an extra . (dot) at the end.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-c2mm-7gpv-8xqx

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

9%
Низкий
больше 4 лет назад
github логотип
GHSA-94wq-jwp8-mvj5

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.13, Thunderbird before 2.0.0.13, and SeaMonkey before 1.1.9 allows remote attackers to inject arbitrary web script or HTML via event handlers, aka "Universal XSS using event handlers."

3%
Низкий
больше 4 лет назад
github логотип
GHSA-pcv9-8f4w-qrgp

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 3.6.24 and 4.x through 7 allows remote attackers to inject arbitrary web script or HTML via vectors involving HTTP 0.9 errors, non-default ports, and content-sniffing.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-j282-cmxq-gm6v

Mozilla Firefox through 1.5.0.3 has a vulnerability in processing the content-length header

1%
Низкий
больше 4 лет назад
github логотип
GHSA-jpfq-gv6p-4pv8

Mozilla Firefox prior to 3.6 has a DoS vulnerability due to an issue in the validation of certificates.

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
github логотип
GHSA-wg6h-56g7-mfvv

Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets

1%
Низкий
больше 4 лет назад
github логотип
GHSA-7c9h-gj9v-x83c

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

0%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться