Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

debian логотип

CVE-2021-23971

больше 5 лет назад

When processing a redirect with a conflicting Referrer-Policy, Firefox ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23970

больше 5 лет назад

Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2021-23970

больше 5 лет назад

Context-specific code was included in a shared jump table; resulting i ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-23969

больше 5 лет назад

As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the source file to be the destination of the redirects. This was fixed to be the redirect destination's origin. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-23969

больше 5 лет назад

As specified in the W3C Content Security Policy draft, when creating a ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-23968

больше 5 лет назад

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-23968

больше 5 лет назад

If Content Security Policy blocked frame navigation, the full destinat ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-23972

больше 5 лет назад

One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2021-23968

больше 5 лет назад

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-23976

больше 5 лет назад

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2021-23971

When processing a redirect with a conflicting Referrer-Policy, Firefox ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23970

Context-specific code was included in a shared jump table; resulting in assertions being triggered in multithreaded wasm code. This vulnerability affects Firefox < 86.

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23970

Context-specific code was included in a shared jump table; resulting i ...

CVSS3: 6.5
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23969

As specified in the W3C Content Security Policy draft, when creating a violation report, "User agents need to ensure that the source file is the URL requested by the page, pre-redirects. If that’s not possible, user agents need to strip the URL down to an origin to avoid unintentional leakage." Under certain types of redirects, Firefox incorrectly set the source file to be the destination of the redirects. This was fixed to be the redirect destination's origin. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23969

As specified in the W3C Content Security Policy draft, when creating a ...

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-23968

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-23968

If Content Security Policy blocked frame navigation, the full destinat ...

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23972

One phishing tactic on the web is to provide a link with HTTP Auth. For example 'https://www.phishingtarget.com@evil.com'. To mitigate this type of attack, Firefox will display a warning dialog; however, this warning dialog would not have been displayed if evil.com used a redirect that was cached by the browser. This vulnerability affects Firefox < 86.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23968

If Content Security Policy blocked frame navigation, the full destination of a redirect served in the frame was reported in the violation report; as opposed to the original frame URI. This could be used to leak sensitive information contained in such URIs. This vulnerability affects Firefox < 86, Thunderbird < 78.8, and Firefox ESR < 78.8.

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2021-23976

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. Note: This issue is a different issue from CVE-2020-26954 and only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 86.

CVSS3: 8.1
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться