Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2018-5124

больше 7 лет назад

Unsanitized output in the browser UI leaves HTML tags in place and can ...

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2018-18511

больше 7 лет назад

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-18511

больше 7 лет назад

Cross-origin images can be read from a canvas element in violation of ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-18510

больше 7 лет назад

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-18510

больше 7 лет назад

The about:crashcontent and about:crashparent pages can be triggered by ...

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-18511

больше 7 лет назад

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2018-18510

больше 7 лет назад

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-5124

больше 7 лет назад

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2019-9792

больше 7 лет назад

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2019-9801

больше 7 лет назад

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-5124

Unsanitized output in the browser UI leaves HTML tags in place and can ...

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18511

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18511

Cross-origin images can be read from a canvas element in violation of ...

CVSS3: 4.3
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18510

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18510

The about:crashcontent and about:crashparent pages can be triggered by ...

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-18511

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
2%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-18510

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2018-5124

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

CVSS3: 6.1
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2019-9792

The IonMonkey just-in-time (JIT) compiler can leak an internal JS_OPTIMIZED_OUT magic value to the running script during a bailout. This magic value can then be used by JavaScript to achieve memory corruption, which results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 9.8
13%
Средний
больше 7 лет назад
ubuntu логотип
CVE-2019-9801

Firefox will accept any registered Program ID as an external protocol handler and offer to launch this local application when given a matching URL on Windows operating systems. This should only happen if the program has specifically registered itself as a "URL Handler" in the Windows registry. *Note: This issue only affects Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Thunderbird < 60.6, Firefox ESR < 60.6, and Firefox < 66.

CVSS3: 5.3
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться