Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

ubuntu логотип

CVE-2020-16012

больше 5 лет назад

Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-35114

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-35114

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 83. ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-35113

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-35113

больше 5 лет назад

Mozilla developers reported memory safety bugs present in Firefox 83 a ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-35112

больше 5 лет назад

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-35112

больше 5 лет назад

If a user downloaded a file lacking an extension on Windows, and then ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-35111

больше 5 лет назад

When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-35111

больше 5 лет назад

When an extension with the proxy permission registered to receive <all ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-26979

больше 5 лет назад

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it. This vulnerability affects Firefox < 84.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2020-16012

Side-channel information leakage in graphics in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

CVSS3: 4.3
3%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-35114

Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-35114

Mozilla developers reported memory safety bugs present in Firefox 83. ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-35113

Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-35113

Mozilla developers reported memory safety bugs present in Firefox 83 a ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-35112

If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-35112

If a user downloaded a file lacking an extension on Windows, and then ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-35111

When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-35111

When an extension with the proxy permission registered to receive <all ...

CVSS3: 4.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26979

When a user typed a URL in the address bar or the search bar and quickly hit the enter key, a website could sometimes capture that event and then redirect the user before navigation occurred to the desired, entered address. To construct a convincing spoof the attacker would have had to guess what the user was typing, perhaps by suggesting it. This vulnerability affects Firefox < 84.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться