Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

ubuntu логотип

CVE-2017-7776

больше 7 лет назад

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

CVSS3: 8.1
EPSS: Низкий
ubuntu логотип

CVE-2017-7777

больше 7 лет назад

Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-7773

больше 7 лет назад

Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-7774

больше 7 лет назад

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2017-7772

больше 7 лет назад

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2017-7772

больше 7 лет назад

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 i ...

CVSS3: 8.8
EPSS: Низкий
ubuntu логотип

CVE-2017-7772

больше 7 лет назад

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2019-9810

больше 7 лет назад

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

CVSS3: 8.8
EPSS: Средний
redhat логотип

CVE-2019-9813

больше 7 лет назад

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

CVSS3: 8.8
EPSS: Низкий
redhat логотип

CVE-2018-18506

больше 7 лет назад

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.

CVSS3: 6.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2017-7776

Heap-based Buffer Overflow read in Graphite2 library in Firefox before 54 in graphite2::Silf::getClassGlyph.

CVSS3: 8.1
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-7777

Use of uninitialized memory in Graphite2 library in Firefox before 54 in graphite2::GlyphCache::Loader::read_glyph function.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-7773

Heap-based Buffer Overflow write in Graphite2 library in Firefox before 54 in lz4::decompress src/Decompressor.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-7774

Out-of-bounds read in Graphite2 Library in Firefox before 54 in graphite2::Silf::readGraphite function.

CVSS3: 9.1
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2017-7772

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2017-7772

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 i ...

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
ubuntu логотип
CVE-2017-7772

Heap-based Buffer Overflow in Graphite2 library in Firefox before 54 in lz4::decompress function.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
redhat логотип
CVE-2019-9810

Incorrect alias information in IonMonkey JIT compiler for Array.prototype.slice method may lead to missing bounds check and a buffer overflow. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

CVSS3: 8.8
30%
Средний
больше 7 лет назад
redhat логотип
CVE-2019-9813

Incorrect handling of __proto__ mutations may lead to type confusion in IonMonkey JIT code and can be leveraged for arbitrary memory read and write. This vulnerability affects Firefox < 66.0.1, Firefox ESR < 60.6.1, and Thunderbird < 60.6.1.

CVSS3: 8.8
6%
Низкий
больше 7 лет назад
redhat логотип
CVE-2018-18506

When proxy auto-detection is enabled, if a web server serves a Proxy Auto-Configuration (PAC) file or if a PAC file is loaded locally, this PAC file can specify that requests to the localhost are to be sent through the proxy to another server. This behavior is disallowed by default when a proxy is manually configured, but when enabled could allow for attacks on services and tools that bind to the localhost for networked behavior if they are accessed through browsing. This vulnerability affects Firefox < 65.

CVSS3: 6.1
2%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться