Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2019-11757

больше 6 лет назад

When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11757

больше 6 лет назад

When following the value's prototype chain, it was possible to retain ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11756

больше 6 лет назад

Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11756

больше 6 лет назад

Improper refcounting of soft token session objects could cause a use-a ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11745

больше 6 лет назад

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11745

больше 6 лет назад

When encrypting with a block cipher, if a call to NSC_EncryptUpdate wa ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-11763

больше 6 лет назад

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-11762

больше 6 лет назад

If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-11757

больше 6 лет назад

When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2019-11760

больше 6 лет назад

A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-11757

When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11757

When following the value's prototype chain, it was possible to retain ...

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11756

Improper refcounting of soft token session objects could cause a use-after-free and crash (likely limited to a denial of service). This vulnerability affects Firefox < 71.

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11756

Improper refcounting of soft token session objects could cause a use-a ...

CVSS3: 8.8
2%
Низкий
больше 6 лет назад
nvd логотип
CVE-2019-11745

When encrypting with a block cipher, if a call to NSC_EncryptUpdate was made with data smaller than the block size, a small out of bounds write could occur. This could have caused heap corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3, and Firefox < 71.

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
debian логотип
CVE-2019-11745

When encrypting with a block cipher, if a call to NSC_EncryptUpdate wa ...

CVSS3: 8.8
3%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11763

Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could have led to XSS in a web application under certain conditions. It could have also led to HTML entities being masked from filters - enabling the use of entities to mask the actual characters of interest from filters. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11762

If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 6.1
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11757

When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitable crash. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2019-11760

A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderbird < 68.2, and Firefox ESR < 68.2.

CVSS3: 8.8
1%
Низкий
больше 6 лет назад

Уязвимостей на страницу


Поделиться