Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

debian логотип

CVE-2021-43534

больше 4 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-43533

больше 4 лет назад

When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-43533

больше 4 лет назад

When parsing internationalized domain names, high bits of the characte ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-43532

больше 4 лет назад

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affects Firefox < 94.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-43532

больше 4 лет назад

The 'Copy Image Link' context menu action would copy the final image U ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-43531

больше 4 лет назад

When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web Extension should have access to. This was fixed to provide the pre-redirect URL. This is related to CVE-2021-43532 but in the context of Web Extensions. This vulnerability affects Firefox < 94.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-43531

больше 4 лет назад

When a user loaded a Web Extensions context menu, the Web Extension co ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-43530

больше 4 лет назад

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-43530

больше 4 лет назад

A Universal XSS vulnerability was present in Firefox for Android resul ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-38510

больше 4 лет назад

The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-43534

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-43533

When parsing internationalized domain names, high bits of the characters in the URLs were sometimes stripped, resulting in inconsistencies that could lead to user confusion or attacks such as phishing. This vulnerability affects Firefox < 94.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-43533

When parsing internationalized domain names, high bits of the characte ...

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-43532

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affects Firefox < 94.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-43532

The 'Copy Image Link' context menu action would copy the final image U ...

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-43531

When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web Extension should have access to. This was fixed to provide the pre-redirect URL. This is related to CVE-2021-43532 but in the context of Web Extensions. This vulnerability affects Firefox < 94.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-43531

When a user loaded a Web Extensions context menu, the Web Extension co ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-43530

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-43530

A Universal XSS vulnerability was present in Firefox for Android resul ...

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-38510

The executable file warning was not presented when downloading .inetloc files, which, due to a flaw in Mac OS, can run commands on a user's computer.*Note: This issue only affected Mac OS operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 8.8
1%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться