Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 561

debian логотип

CVE-2020-26979

больше 5 лет назад

When a user typed a URL in the address bar or the search bar and quick ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-26978

больше 5 лет назад

Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2020-26978

больше 5 лет назад

Using techniques that built on the slipstream research, a malicious we ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2020-26976

больше 5 лет назад

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-26976

больше 5 лет назад

When a HTTPS pages was embedded in a HTTP page, and there was a servic ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-26974

больше 5 лет назад

When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-26974

больше 5 лет назад

When flex-basis was used on a table wrapper, a StyleGenericFlexBasis o ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-26973

больше 5 лет назад

Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-26973

больше 5 лет назад

Certain input to the CSS Sanitizer confused it, resulting in incorrect ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-26972

больше 5 лет назад

The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2020-26979

When a user typed a URL in the address bar or the search bar and quick ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26978

Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26978

Using techniques that built on the slipstream research, a malicious we ...

CVSS3: 6.1
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26976

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

CVSS3: 6.5
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26976

When a HTTPS pages was embedded in a HTTP page, and there was a servic ...

CVSS3: 6.5
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26974

When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26974

When flex-basis was used on a table wrapper, a StyleGenericFlexBasis o ...

CVSS3: 8.8
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26973

Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

CVSS3: 8.8
2%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-26973

Certain input to the CSS Sanitizer confused it, resulting in incorrect ...

CVSS3: 8.8
2%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-26972

The lifecycle of IPC Actors allows managed actors to outlive their manager actors; and the former must ensure that they are not attempting to use a dead actor they have a reference to. Such a check was omitted in WebGL, resulting in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 84.

CVSS3: 9.8
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться