Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

suse-cvrf логотип

SUSE-SU-2019:1684-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:1682-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Средний
suse-cvrf логотип

SUSE-SU-2019:1629-1

около 7 лет назад

Security update for MozillaFirefox

EPSS: Средний
suse-cvrf логотип

SUSE-RU-2019:1625-1

около 7 лет назад

Recommended update for MozillaFirefox

EPSS: Средний
redhat логотип

CVE-2019-11708

около 7 лет назад

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

CVSS3: 10
EPSS: Средний
redhat логотип

CVE-2019-11707

около 7 лет назад

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
EPSS: Средний
fstec логотип

BDU:2019-02947

около 7 лет назад

Уязвимость браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, существующая из-за недостаточной проверки параметров в сообщениях Prompt:Open IPC между дочерним и родительским процессами, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
EPSS: Средний
redhat логотип

CVE-2019-11702

около 7 лет назад

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2019-11693

больше 7 лет назад

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2019-11698

больше 7 лет назад

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
suse-cvrf логотип
SUSE-SU-2019:1684-1

Security update for MozillaFirefox

56%
Средний
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1682-1

Security update for MozillaFirefox

56%
Средний
около 7 лет назад
suse-cvrf логотип
SUSE-SU-2019:1629-1

Security update for MozillaFirefox

38%
Средний
около 7 лет назад
suse-cvrf логотип
SUSE-RU-2019:1625-1

Recommended update for MozillaFirefox

38%
Средний
около 7 лет назад
redhat логотип
CVE-2019-11708

Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxed parent process opening web content chosen by a compromised child process. When combined with additional vulnerabilities this could result in executing arbitrary code on the user's computer. This vulnerability affects Firefox ESR < 60.7.2, Firefox < 67.0.4, and Thunderbird < 60.7.2.

CVSS3: 10
56%
Средний
около 7 лет назад
redhat логотип
CVE-2019-11707

A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop. This can allow for an exploitable crash. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 60.7.1, Firefox < 67.0.3, and Thunderbird < 60.7.2.

CVSS3: 8.8
38%
Средний
около 7 лет назад
fstec логотип
BDU:2019-02947

Уязвимость браузеров Firefox ESR, Firefox и почтового клиента Thunderbird, существующая из-за недостаточной проверки параметров в сообщениях Prompt:Open IPC между дочерним и родительским процессами, позволяющая нарушителю выполнить произвольный код

CVSS3: 10
56%
Средний
около 7 лет назад
redhat логотип
CVE-2019-11702

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

CVSS3: 6.1
1%
Низкий
около 7 лет назад
redhat логотип
CVE-2019-11693

The bufferdata function in WebGL is vulnerable to a buffer overflow with specific graphics drivers on Linux. This could result in malicious content freezing a tab or triggering a potentially exploitable crash. *Note: this issue only occurs on Linux. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 9.8
2%
Низкий
больше 7 лет назад
redhat логотип
CVE-2019-11698

If a crafted hyperlink is dragged and dropped to the bookmark bar or sidebar and the resulting bookmark is subsequently dragged and dropped into the web content area, an arbitrary query of a user's browser history can be run and transmitted to the content page via drop event data. This allows for the theft of browser history by a malicious site. This vulnerability affects Thunderbird < 60.7, Firefox < 67, and Firefox ESR < 60.7.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться