Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2019-11714

около 7 лет назад

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-11714

около 7 лет назад

Necko can access a child on the wrong thread during UDP connections, r ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-11713

около 7 лет назад

A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-11713

около 7 лет назад

A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/ ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-11712

около 7 лет назад

POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11712

около 7 лет назад

POST requests made by NPAPI plugins, such as Flash, that receive a sta ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11711

около 7 лет назад

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2019-11711

около 7 лет назад

When an inner window is reused, it does not consider the use of docume ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2019-11710

около 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 68.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-11710

около 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-11714

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.

CVSS3: 9.8
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11714

Necko can access a child on the wrong thread during UDP connections, r ...

CVSS3: 9.8
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11713

A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/2 stream is closed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 9.8
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11713

A use-after-free vulnerability can occur in HTTP/2 when a cached HTTP/ ...

CVSS3: 9.8
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11712

POST requests made by NPAPI plugins, such as Flash, that receive a status 308 redirect response can bypass CORS requirements. This can allow an attacker to perform Cross-Site Request Forgery (CSRF) attacks. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11712

POST requests made by NPAPI plugins, such as Flash, that receive a sta ...

CVSS3: 8.8
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11711

When an inner window is reused, it does not consider the use of document.domain for cross-origin protections. If pages on different subdomains ever cooperatively use document.domain, then either page can abuse this to inject script into arbitrary pages on the other subdomain, even those that did not use document.domain to relax their origin security. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 8.8
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11711

When an inner window is reused, it does not consider the use of docume ...

CVSS3: 8.8
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11710

Mozilla developers and community members reported memory safety bugs present in Firefox 67. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 68.

CVSS3: 9.8
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11710

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
2%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться