Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 545

nvd логотип

CVE-2020-15652

около 6 лет назад

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-15652

около 6 лет назад

By observing the stack trace for JavaScript errors in web workers, it ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-15651

около 6 лет назад

A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-15651

около 6 лет назад

A unicode RTL order character in the downloaded file name can be used ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-15648

около 6 лет назад

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-15648

около 6 лет назад

Using object or embed tags, it was possible to frame other websites, e ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-15647

около 6 лет назад

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2020-15647

около 6 лет назад

A Content Provider in Firefox for Android allowed local files accessib ...

CVSS3: 7.4
EPSS: Низкий
ubuntu логотип

CVE-2020-15648

около 6 лет назад

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2020-15647

около 6 лет назад

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-15652

By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulnerability affects Firefox < 79, Firefox ESR < 68.11, Firefox ESR < 78.1, Thunderbird < 68.11, and Thunderbird < 78.1.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
debian логотип
CVE-2020-15652

By observing the stack trace for JavaScript errors in web workers, it ...

CVSS3: 6.5
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-15651

A unicode RTL order character in the downloaded file name can be used to change the file's name during the download UI flow to change the file extension. This vulnerability affects Firefox for iOS < 28.

CVSS3: 4.3
1%
Низкий
около 6 лет назад
debian логотип
CVE-2020-15651

A unicode RTL order character in the downloaded file name can be used ...

CVSS3: 4.3
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-15648

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
debian логотип
CVE-2020-15648

Using object or embed tags, it was possible to frame other websites, e ...

CVSS3: 6.5
1%
Низкий
около 6 лет назад
nvd логотип
CVE-2020-15647

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

CVSS3: 7.4
1%
Низкий
около 6 лет назад
debian логотип
CVE-2020-15647

A Content Provider in Firefox for Android allowed local files accessib ...

CVSS3: 7.4
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2020-15648

Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.

CVSS3: 6.5
1%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2020-15647

A Content Provider in Firefox for Android allowed local files accessible by the browser to be read by a remote webpage, leading to sensitive data disclosure, including cookies for other origins. This vulnerability affects Firefox for < Android.

CVSS3: 7.4
1%
Низкий
около 6 лет назад

Уязвимостей на страницу


Поделиться