Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2019-11719

около 7 лет назад

When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-11719

около 7 лет назад

When importing a curve25519 private key in PKCS#8format with leading 0 ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-11718

около 7 лет назад

Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-11718

около 7 лет назад

Activity Stream can display content from sent from the Snippet Service ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-11717

около 7 лет назад

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-11717

около 7 лет назад

A vulnerability exists where the caret ("^") character is improperly e ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-11716

около 7 лет назад

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

CVSS3: 8.3
EPSS: Низкий
debian логотип

CVE-2019-11716

около 7 лет назад

Until explicitly accessed by script, window.globalThis is not enumerab ...

CVSS3: 8.3
EPSS: Низкий
nvd логотип

CVE-2019-11715

около 7 лет назад

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-11715

около 7 лет назад

Due to an error while parsing page content, it is possible for properl ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-11719

When importing a curve25519 private key in PKCS#8format with leading 0x00 bytes, it is possible to trigger an out-of-bounds read in the Network Security Services (NSS) library. This could lead to information disclosure. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 7.5
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11719

When importing a curve25519 private key in PKCS#8format with leading 0 ...

CVSS3: 7.5
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11718

Activity Stream can display content from sent from the Snippet Service website. This content is written to innerHTML on the Activity Stream page without sanitization, allowing for a potential access to other information available to the Activity Stream, such as browsing history, if the Snipper Service were compromised. This vulnerability affects Firefox < 68.

CVSS3: 5.3
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11718

Activity Stream can display content from sent from the Snippet Service ...

CVSS3: 5.3
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11717

A vulnerability exists where the caret ("^") character is improperly escaped constructing some URIs due to it being used as a separator, allowing for possible spoofing of origin attributes. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 5.3
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11717

A vulnerability exists where the caret ("^") character is improperly e ...

CVSS3: 5.3
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11716

Until explicitly accessed by script, window.globalThis is not enumerable and, as a result, is not visible to code such as Object.getOwnPropertyNames(window). Sites that deploy a sandboxing that depends on enumerating and freezing access to the window object may miss this, allowing their sandboxes to be bypassed. This vulnerability affects Firefox < 68.

CVSS3: 8.3
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11716

Until explicitly accessed by script, window.globalThis is not enumerab ...

CVSS3: 8.3
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11715

Due to an error while parsing page content, it is possible for properly sanitized user input to be misinterpreted and lead to XSS hazards on web sites in certain circumstances. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 6.1
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11715

Due to an error while parsing page content, it is possible for properl ...

CVSS3: 6.1
2%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться