Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

debian логотип

CVE-2021-23976

больше 5 лет назад

When accepting a malicious intent from other installed apps, Firefox f ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2021-23975

больше 5 лет назад

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23975

больше 5 лет назад

The developer page about:memory has a Measure function for exploring w ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23974

больше 5 лет назад

The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2021-23974

больше 5 лет назад

The DOMParser API did not properly process '<noscript>' elements for e ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2021-23973

больше 5 лет назад

When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23973

больше 5 лет назад

When trying to load a cross-origin resource in an audio/video context ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23972

больше 5 лет назад

One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2021-23972

больше 5 лет назад

One phishing tactic on the web is to provide a link with HTTP Auth. Fo ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2021-23971

больше 5 лет назад

When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-23976

When accepting a malicious intent from other installed apps, Firefox f ...

CVSS3: 8.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23975

The developer page about:memory has a Measure function for exploring what object types the browser has allocated and their sizes. When this function was invoked we incorrectly called the sizeof function, instead of using the API method that checks for invalid pointers. This vulnerability affects Firefox < 86.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23975

The developer page about:memory has a Measure function for exploring w ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23974

The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23974

The DOMParser API did not properly process '<noscript>' elements for e ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23973

When trying to load a cross-origin resource in an audio/video context a decoding error may have resulted, and the content of that error may have revealed information about the resource. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23973

When trying to load a cross-origin resource in an audio/video context ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23972

One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23972

One phishing tactic on the web is to provide a link with HTTP Auth. Fo ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23971

When processing a redirect with a conflicting Referrer-Policy, Firefox would have adopted the redirect's Referrer-Policy. This would have potentially resulted in more information than intended by the original origin being provided to the destination of the redirect. This vulnerability affects Firefox < 86.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться