Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

redhat логотип

CVE-2020-6820

больше 6 лет назад

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2020-6819

больше 6 лет назад

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-6815

больше 6 лет назад

Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 74.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-6815

больше 6 лет назад

Mozilla developers reported memory safety and script safety bugs prese ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-6814

больше 6 лет назад

Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2020-6814

больше 6 лет назад

Mozilla developers reported memory safety bugs present in Firefox and ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2020-6813

больше 6 лет назад

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-6813

больше 6 лет назад

When protecting CSS blocks with the nonce feature of Content Security ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-6812

больше 6 лет назад

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-6812

больше 6 лет назад

The first time AirPods are connected to an iPhone, they become named a ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2020-6820

Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.8
6%
Низкий
больше 6 лет назад
redhat логотип
CVE-2020-6819

Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Thunderbird < 68.7.0, Firefox < 74.0.1, and Firefox ESR < 68.6.1.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6815

Mozilla developers reported memory safety and script safety bugs present in Firefox 73. Some of these bugs showed evidence of memory corruption or escalation of privilege and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 74.

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6815

Mozilla developers reported memory safety and script safety bugs prese ...

CVSS3: 9.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6814

Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 9.8
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6814

Mozilla developers reported memory safety bugs present in Firefox and ...

CVSS3: 9.8
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6813

When protecting CSS blocks with the nonce feature of Content Security Policy, the @import statement in the CSS block could allow an attacker to inject arbitrary styles, bypassing the intent of the Content Security Policy. This vulnerability affects Firefox < 74.

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6813

When protecting CSS blocks with the nonce feature of Content Security ...

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6812

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 5.3
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6812

The first time AirPods are connected to an iPhone, they become named a ...

CVSS3: 5.3
2%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться