Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

nvd логотип

CVE-2021-23983

больше 5 лет назад

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23983

больше 5 лет назад

By causing a transition on a parent node by removing a CSS rule, an in ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23982

больше 5 лет назад

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23982

больше 5 лет назад

Using techniques that built on the slipstream research, a malicious we ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23981

больше 5 лет назад

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2021-23981

больше 5 лет назад

A texture upload of a Pixel Buffer Object could have confused the WebG ...

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2021-23983

больше 5 лет назад

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-23981

больше 5 лет назад

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2021-23986

больше 5 лет назад

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2021-23988

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 87.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2021-23983

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23983

By causing a transition on a parent node by removing a CSS rule, an in ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23982

Using techniques that built on the slipstream research, a malicious webpage could have scanned both an internal network's hosts as well as services running on the user's local machine utilizing WebRTC connections. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23982

Using techniques that built on the slipstream research, a malicious we ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23981

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23981

A texture upload of a Pixel Buffer Object could have confused the WebG ...

CVSS3: 8.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23983

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23981

A texture upload of a Pixel Buffer Object could have confused the WebGL code to skip binding the buffer used to unpack it, resulting in memory corruption and a potentially exploitable information leak or crash. This vulnerability affects Firefox ESR < 78.9, Firefox < 87, and Thunderbird < 78.9.

CVSS3: 8.1
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23986

A malicious extension with the 'search' permission could have installed a new search engine whose favicon referenced a cross-origin URL. The response to this cross-origin request could have been read by the extension, allowing a same-origin policy bypass by the extension, which should not have cross-origin permissions. This cross-origin request was made without cookies, so the sensitive information disclosed by the violation was limited to local-network resources or resources that perform IP-based authentication. This vulnerability affects Firefox < 87.

CVSS3: 6.5
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23988

Mozilla developers reported memory safety bugs present in Firefox 86. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 87.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться