Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2019-9803

больше 7 лет назад

The Upgrade-Insecure-Requests (UIR) specification states that if UIR i ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2019-9802

больше 7 лет назад

If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and allow for a potential memory read of adjacent data from the privileged Chrome process, which may include sensitive data. This vulnerability affects Firefox < 66.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-9802

больше 7 лет назад

If a Sandbox content process is compromised, it can initiate an FTP do ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-9801

больше 7 лет назад

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2019-9801

больше 7 лет назад

Firefox will accept any registered Program ID as an external protocol ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2019-9799

больше 7 лет назад

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2019-9799

больше 7 лет назад

Insufficient bounds checking of data during inter-process communicatio ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2019-9798

больше 7 лет назад

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2019-9798

больше 7 лет назад

On Android systems, Firefox can load a library from APITRACE_LIB, whic ...

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2019-9797

больше 7 лет назад

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2019-9803

The Upgrade-Insecure-Requests (UIR) specification states that if UIR i ...

CVSS3: 7.4
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-9802

If a Sandbox content process is compromised, it can initiate an FTP download which will then use a child process to render the downloaded data. The downloaded data can then be passed to the Chrome process with an arbitrary file length supplied by an attacker, bypassing sandbox protections and allow for a potential memory read of adjacent data from the privileged Chrome process, which may include sensitive data. This vulnerability affects Firefox < 66.

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-9802

If a Sandbox content process is compromised, it can initiate an FTP do ...

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-9801

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 5.3
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-9801

Firefox will accept any registered Program ID as an external protocol ...

CVSS3: 5.3
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-9799

Insufficient bounds checking of data during inter-process communication might allow a compromised content process to be able to read memory from the parent process under certain conditions. This vulnerability affects Firefox < 66.

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-9799

Insufficient bounds checking of data during inter-process communicatio ...

CVSS3: 7.5
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-9798

On Android systems, Firefox can load a library from APITRACE_LIB, which is writable by all users and applications. This could allow malicious third party applications to execute a man-in-the-middle attack if a malicious code was written to that location and loaded. *Note: This issue only affects Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 66.

CVSS3: 7.4
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2019-9798

On Android systems, Firefox can load a library from APITRACE_LIB, whic ...

CVSS3: 7.4
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2019-9797

Cross-origin images can be read in violation of the same-origin policy by exporting an image after using createImageBitmap to read the image and then rendering the resulting bitmap image within a canvas element. This vulnerability affects Firefox < 66.

CVSS3: 5.3
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться