Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2019-9800

около 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-9800

около 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-11730

около 7 лет назад

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
EPSS: Средний
debian логотип

CVE-2019-11730

около 7 лет назад

A vulnerability exists where if a user opens a locally saved HTML file ...

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2019-11729

около 7 лет назад

Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-11729

около 7 лет назад

Empty or malformed p256-ECDH public keys may trigger a segmentation fa ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-11728

около 7 лет назад

The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.

CVSS3: 4.7
EPSS: Низкий
debian логотип

CVE-2019-11728

около 7 лет назад

The HTTP Alternative Services header, Alt-Svc, can be used by a malici ...

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2019-11727

около 7 лет назад

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-11727

около 7 лет назад

A vulnerability exists where it possible to force Network Security Ser ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-9800

Mozilla developers and community members reported memory safety bugs present in Firefox 66, Firefox ESR 60.6, and Thunderbird 60.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 9.8
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-9800

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file, this file can use file: URIs to access other files in the same directory or sub-directories if the names are known or guessed. The Fetch API can then be used to read the contents of any files stored in these directories and they may uploaded to a server. It was demonstrated that in combination with a popular Android messaging app, if a malicious HTML attachment is sent to a user and they opened that attachment in Firefox, due to that app's predictable pattern for locally-saved file names, it is possible to read attachments the victim received from other correspondents. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.5
20%
Средний
около 7 лет назад
debian логотип
CVE-2019-11730

A vulnerability exists where if a user opens a locally saved HTML file ...

CVSS3: 6.5
20%
Средний
около 7 лет назад
nvd логотип
CVE-2019-11729

Empty or malformed p256-ECDH public keys may trigger a segmentation fault due values being improperly sanitized before being copied into memory and used. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 7.5
3%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11729

Empty or malformed p256-ECDH public keys may trigger a segmentation fa ...

CVSS3: 7.5
3%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11728

The HTTP Alternative Services header, Alt-Svc, can be used by a malicious site to scan all TCP ports of any host that the accessible to a user when web content is loaded. This vulnerability affects Firefox < 68.

CVSS3: 4.7
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11728

The HTTP Alternative Services header, Alt-Svc, can be used by a malici ...

CVSS3: 4.7
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11727

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

CVSS3: 5.3
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11727

A vulnerability exists where it possible to force Network Security Ser ...

CVSS3: 5.3
2%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться