Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2020-6811

больше 6 лет назад

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-6811

больше 6 лет назад

The 'Copy as cURL' feature of Devtools' network tab did not properly e ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2020-6810

больше 6 лет назад

After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks. This vulnerability affects Firefox < 74.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2020-6810

больше 6 лет назад

After a website had entered fullscreen mode, it could have used a prev ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2020-6809

больше 6 лет назад

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2020-6809

больше 6 лет назад

When a Web Extension had the all-urls permission and made a fetch requ ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2020-6808

больше 6 лет назад

When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for example) was the originating javascript: URL which could lead to spoofing attacks; it is now correctly the URL of the originating document. This vulnerability affects Firefox < 74.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2020-6808

больше 6 лет назад

When a JavaScript URL (javascript:) is evaluated and the result is a s ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2020-6807

больше 6 лет назад

When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2020-6807

больше 6 лет назад

When a device was changed while a stream was about to be destroyed, th ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2020-6811

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6811

The 'Copy as cURL' feature of Devtools' network tab did not properly e ...

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6810

After a website had entered fullscreen mode, it could have used a previously opened popup to obscure the notification that indicates the browser is in fullscreen mode. Combined with spoofing the browser chrome, this could have led to confusing the user about the current origin of the page and credential theft or other attacks. This vulnerability affects Firefox < 74.

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6810

After a website had entered fullscreen mode, it could have used a prev ...

CVSS3: 4.3
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6809

When a Web Extension had the all-urls permission and made a fetch request with a mode set to 'same-origin', it was possible for the Web Extension to read local files. This vulnerability affects Firefox < 74.

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6809

When a Web Extension had the all-urls permission and made a fetch requ ...

CVSS3: 7.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6808

When a JavaScript URL (javascript:) is evaluated and the result is a string, this string is parsed to create an HTML document, which is then presented. Previously, this document's URL (as reported by the document.location property, for example) was the originating javascript: URL which could lead to spoofing attacks; it is now correctly the URL of the originating document. This vulnerability affects Firefox < 74.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6808

When a JavaScript URL (javascript:) is evaluated and the result is a s ...

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2020-6807

When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2020-6807

When a device was changed while a stream was about to be destroyed, th ...

CVSS3: 8.8
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться