Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

debian логотип

CVE-2019-17000

больше 6 лет назад

An object tag with a data URI did not correctly inherit the document's ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-11765

больше 6 лет назад

A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulnerability affects Firefox < 70.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-11765

больше 6 лет назад

A compromised content process could send a message to the parent proce ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11764

больше 6 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11764

больше 6 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-17000

больше 6 лет назад

An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URIs. This vulnerability affects Firefox < 70.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-11764

больше 6 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-11765

больше 6 лет назад

A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulnerability affects Firefox < 70.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11763

больше 6 лет назад

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-11763

больше 6 лет назад

Failure to correctly handle null bytes when processing HTML entities r ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-17000

An object tag with a data URI did not correctly inherit the document's ...

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11765

A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulnerability affects Firefox < 70.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11765

A compromised content process could send a message to the parent proce ...

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11764

Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11764

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-17000

An object tag with a data URI did not correctly inherit the document's Content Security Policy. This allowed a CSP bypass in a cross-origin frame if the document's policy explicitly allowed data: URIs. This vulnerability affects Firefox < 70.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11764

Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11765

A compromised content process could send a message to the parent process that would cause the 'Click to Play' permission prompt to be shown. However, due to lack of validation from the parent process, if the user accepted the permission request an attacker-controlled permission would be granted rather than the 'Click to Play' permission. This vulnerability affects Firefox < 70.

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11763

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11763

Failure to correctly handle null bytes when processing HTML entities r ...

CVSS3: 6.1
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться