Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

nvd логотип

CVE-2021-23988

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 87.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-23988

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 86. ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-23987

больше 5 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-23987

больше 5 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-23986

больше 5 лет назад

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23986

больше 5 лет назад

A malicious extension with the 'search' permission could have installe ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23985

больше 5 лет назад

If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user. This would have allowed a remote attacker (able to make a direct network connection to the victim) to monitor the user's browsing activity and (plaintext) network traffic. This was addressed by providing a visual cue when Devtools has an open network socket. This vulnerability affects Firefox < 87.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23985

больше 5 лет назад

If an attacker is able to alter specific about:config values (for exam ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23984

больше 5 лет назад

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23984

больше 5 лет назад

A malicious extension could have opened a popup window lacking an addr ...

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2021-23988

Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 87.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23988

Mozilla developers reported memory safety bugs present in Firefox 86. ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23987

Mozilla developers and community members reported memory safety bugs present in Firefox 86 and Firefox ESR 78.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23987

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23986

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23986

A malicious extension with the 'search' permission could have installe ...

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23985

If an attacker is able to alter specific about:config values (for example malware running on the user's computer), the Devtools remote debugging feature could have been enabled in a way that was unnoticable to the user. This would have allowed a remote attacker (able to make a direct network connection to the victim) to monitor the user's browsing activity and (plaintext) network traffic. This was addressed by providing a visual cue when Devtools has an open network socket. This vulnerability affects Firefox < 87.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23985

If an attacker is able to alter specific about:config values (for exam ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23984

A malicious extension could have opened a popup window lacking an address bar. The title of the popup lacking an address bar should not be fully controllable, but in this situation was. This could have been used to spoof a website and attempt to trick the user into providing credentials. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23984

A malicious extension could have opened a popup window lacking an addr ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться