Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

debian логотип

CVE-2019-11737

почти 7 лет назад

If a wildcard ('*') is specified for the host in Content Security Poli ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-11736

почти 7 лет назад

The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. <br>*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CVSS3: 7
EPSS: Низкий
debian логотип

CVE-2019-11736

почти 7 лет назад

The Mozilla Maintenance Service does not guard against files being har ...

CVSS3: 7
EPSS: Низкий
nvd логотип

CVE-2019-11735

почти 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11735

почти 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11734

почти 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-11734

почти 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-11733

почти 7 лет назад

When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered in the same session, allowing for potential theft of stored passwords. This vulnerability affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-11733

почти 7 лет назад

When a master password is set, it is required to be entered again befo ...

CVSS3: 9.8
EPSS: Низкий
ubuntu логотип

CVE-2019-11743

почти 7 лет назад

Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.

CVSS3: 3.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-11737

If a wildcard ('*') is specified for the host in Content Security Poli ...

CVSS3: 5.3
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-11736

The Mozilla Maintenance Service does not guard against files being hardlinked to another file in the updates directory, allowing for the replacement of local files, including the Maintenance Service executable, which is run with privileged access. Additionally, there was a race condition during checks for junctions and symbolic links by the Maintenance Service, allowing for potential local file and directory manipulation to be undetected in some circumstances. This allows for potential privilege escalation by a user with unprivileged local access. <br>*Note: These attacks requires local system access and only affects Windows. Other operating systems are not affected.*. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CVSS3: 7
0%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-11736

The Mozilla Maintenance Service does not guard against files being har ...

CVSS3: 7
0%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-11735

Mozilla developers and community members reported memory safety bugs present in Firefox 68 and Firefox ESR 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69 and Firefox ESR < 68.1.

CVSS3: 8.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-11735

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-11734

Mozilla developers and community members reported memory safety bugs present in Firefox 68. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 69.

CVSS3: 9.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-11734

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
1%
Низкий
почти 7 лет назад
nvd логотип
CVE-2019-11733

When a master password is set, it is required to be entered again before stored passwords can be accessed in the 'Saved Logins' dialog. It was found that locally stored passwords can be copied to the clipboard thorough the 'copy password' context menu item without re-entering the master password if the master password had been previously entered in the same session, allowing for potential theft of stored passwords. This vulnerability affects Firefox < 68.0.2 and Firefox ESR < 68.0.2.

CVSS3: 9.8
1%
Низкий
почти 7 лет назад
debian логотип
CVE-2019-11733

When a master password is set, it is required to be entered again befo ...

CVSS3: 9.8
1%
Низкий
почти 7 лет назад
ubuntu логотип
CVE-2019-11743

Navigation events were not fully adhering to the W3C's "Navigation-Timing Level 2" draft specification in some instances for the unload event, which restricts access to detailed timing attributes to only be same-origin. This resulted in potential cross-origin information exposure of history through timing side-channel attacks. This vulnerability affects Firefox < 69, Thunderbird < 68.1, Thunderbird < 60.9, Firefox ESR < 60.9, and Firefox ESR < 68.1.

CVSS3: 3.7
2%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться