Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 500

nvd логотип

CVE-2019-11709

около 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2019-11709

около 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2019-11708

около 7 лет назад

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

CVSS3: 10
EPSS: Средний
debian логотип

CVE-2019-11708

около 7 лет назад

Insufficient vetting of parameters passed with the Prompt:Open IPC mes ...

CVSS3: 10
EPSS: Средний
nvd логотип

CVE-2019-11707

около 7 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
EPSS: Средний
debian логотип

CVE-2019-11707

около 7 лет назад

A type confusion vulnerability can occur when manipulating JavaScript ...

CVSS3: 8.8
EPSS: Средний
nvd логотип

CVE-2019-11702

около 7 лет назад

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2019-11702

около 7 лет назад

A hyperlink using protocols associated with Internet Explorer, such as ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2019-11701

около 7 лет назад

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2019-11701

около 7 лет назад

The default webcal: protocol handler will load a web site vulnerable t ...

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2019-11709

Mozilla developers and community members reported memory safety bugs present in Firefox 67 and Firefox ESR 60.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.8, Firefox < 68, and Thunderbird < 60.8.

CVSS3: 9.8
2%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11709

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11708

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

CVSS3: 10
56%
Средний
около 7 лет назад
debian логотип
CVE-2019-11708

Insufficient vetting of parameters passed with the Prompt:Open IPC mes ...

CVSS3: 10
56%
Средний
около 7 лет назад
nvd логотип
CVE-2019-11707

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
38%
Средний
около 7 лет назад
debian логотип
CVE-2019-11707

A type confusion vulnerability can occur when manipulating JavaScript ...

CVSS3: 8.8
38%
Средний
около 7 лет назад
nvd логотип
CVE-2019-11702

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

CVSS3: 6.5
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11702

A hyperlink using protocols associated with Internet Explorer, such as ...

CVSS3: 6.5
1%
Низкий
около 7 лет назад
nvd логотип
CVE-2019-11701

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.

CVSS3: 6.1
1%
Низкий
около 7 лет назад
debian логотип
CVE-2019-11701

The default webcal: protocol handler will load a web site vulnerable t ...

CVSS3: 6.1
1%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться