Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

debian логотип

CVE-2021-38505

больше 4 лет назад

Microsoft introduced a new feature in Windows 10 known as Cloud Clipbo ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-38504

больше 4 лет назад

When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-38504

больше 4 лет назад

When interacting with an HTML input element's file picker dialog with ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-38503

больше 4 лет назад

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 10
EPSS: Низкий
debian логотип

CVE-2021-38503

больше 4 лет назад

The iframe sandbox rules were not correctly applied to XSLT stylesheet ...

CVSS3: 10
EPSS: Низкий
ubuntu логотип

CVE-2021-43544

больше 4 лет назад

When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-43530

больше 4 лет назад

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2021-38506

больше 4 лет назад

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-38509

больше 4 лет назад

Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-43539

больше 4 лет назад

Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-38505

Microsoft introduced a new feature in Windows 10 known as Cloud Clipbo ...

CVSS3: 6.5
1%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-38504

When interacting with an HTML input element's file picker dialog with webkitdirectory set, a use-after-free could have resulted, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-38504

When interacting with an HTML input element's file picker dialog with ...

CVSS3: 8.8
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2021-38503

The iframe sandbox rules were not correctly applied to XSLT stylesheets, allowing an iframe to bypass restrictions such as executing scripts or navigating the top-level frame. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 10
4%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-38503

The iframe sandbox rules were not correctly applied to XSLT stylesheet ...

CVSS3: 10
4%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-43544

When receiving a URL through a SEND intent, Firefox would have searched for the text, but subsequent usages of the address bar might have caused the URL to load unintentionally, which could lead to XSS and spoofing attacks. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 95.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-43530

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

CVSS3: 6.1
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-38506

Through a series of navigations, Firefox could have entered fullscreen mode without notification or warning to the user. This could lead to spoofing attacks on the browser UI including phishing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-38509

Due to an unusual sequence of attacker-controlled events, a Javascript alert() dialog with arbitrary (although unstyled) contents could be displayed over top an uncontrolled webpage of the attacker's choosing. This vulnerability affects Firefox < 94, Thunderbird < 91.3, and Firefox ESR < 91.3.

CVSS3: 4.3
2%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-43539

Failure to correctly record the location of live pointers across wasm instance calls resulted in a GC occurring within the call not tracing those live pointers. This could have led to a use-after-free causing a potentially exploitable crash. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.

CVSS3: 8.8
2%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться