Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2019-9817

около 7 лет назад

Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-9817

около 7 лет назад

Images from a different domain can be read using a canvas object in so ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-9816

около 7 лет назад

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2019-9816

около 7 лет назад

A possible vulnerability exists where type confusion can occur when ma ...

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2019-9815

около 7 лет назад

If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sysctl. Firefox now makes use of it on the main thread and any worker threads. *Note: users need to update to macOS 10.14.5 in order to take advantage of this change.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2019-9815

около 7 лет назад

If hyperthreading is not disabled, a timing attack vulnerability exist ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2019-9814

около 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 67.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-9814

около 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-9811

около 7 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.3
EPSS: Низкий
debian логотип

CVE-2019-9811

около 7 лет назад

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbo ...

CVSS3: 8.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-9817

Images from a different domain can be read using a canvas object in some circumstances. This could be used to steal image data from a different site in violation of same-origin policy. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 5.3
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-9817

Images from a different domain can be read using a canvas object in so ...

CVSS3: 5.3
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-9816

A possible vulnerability exists where type confusion can occur when manipulating JavaScript objects in object groups, allowing for the bypassing of security checks within these groups. *Note: this vulnerability has only been demonstrated with UnboxedObjects, which are disabled by default on all supported releases.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 5.9
6%
Низкий
около 7 лет назад
debian логотип
CVE-2019-9816

A possible vulnerability exists where type confusion can occur when ma ...

CVSS3: 5.9
6%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-9815

If hyperthreading is not disabled, a timing attack vulnerability exists, similar to previous Spectre attacks. Apple has shipped macOS 10.14.5 with an option to disable hyperthreading in applications running untrusted code in a thread through a new sysctl. Firefox now makes use of it on the main thread and any worker threads. *Note: users need to update to macOS 10.14.5 in order to take advantage of this change.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 8.1
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-9815

If hyperthreading is not disabled, a timing attack vulnerability exist ...

CVSS3: 8.1
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-9814

Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 67.

CVSS3: 9.8
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-9814

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-9811

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbox escape by installing a malicious language pack and then opening a browser feature that used the compromised translation. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.3
3%
Низкий
около 7 лет назад
debian логотип
CVE-2019-9811

As part of a winning Pwn2Own entry, a researcher demonstrated a sandbo ...

CVSS3: 8.3
3%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться