Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2019-11762

больше 6 лет назад

If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-11762

больше 6 лет назад

If two same-origin documents set document.domain differently to become ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2019-11761

больше 6 лет назад

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2019-11761

больше 6 лет назад

By using a form with a data URI it was possible to gain access to the ...

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2019-11760

больше 6 лет назад

A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11760

больше 6 лет назад

A fixed-size stack buffer could overflow in nrappkit when doing WebRTC ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11759

больше 6 лет назад

An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11759

больше 6 лет назад

An attacker could have caused 4 bytes of HMAC output to be written pas ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11758

больше 6 лет назад

Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11758

больше 6 лет назад

Mozilla community member Philipp reported a memory safety bug present ...

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-11762

If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11762

If two same-origin documents set document.domain differently to become ...

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11761

By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it was a bypass of existing defense in depth mechanisms. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11761

By using a form with a data URI it was possible to gain access to the ...

CVSS3: 5.4
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11760

A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11760

A fixed-size stack buffer could overflow in nrappkit when doing WebRTC ...

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11759

An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11759

An attacker could have caused 4 bytes of HMAC output to be written pas ...

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11758

Mozilla community member Philipp reported a memory safety bug present in Firefox 68 when 360 Total Security was installed. This bug showed evidence of memory corruption in the accessibility engine and we presume that with enough effort that it could be exploited to run arbitrary code. This vulnerability affects Firefox < 69, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11758

Mozilla community member Philipp reported a memory safety bug present ...

CVSS3: 8.8
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться