Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2018-18497

больше 7 лет назад

Limitations on the URIs allowed to WebExtensions by the browser.window ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-18496

больше 7 лет назад

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-18496

больше 7 лет назад

When the RSS Feed preview about:feeds page is framed within another pa ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-18495

больше 7 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-18495

больше 7 лет назад

WebExtension content scripts can be loaded into about: pages in some c ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-18494

больше 7 лет назад

A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-18494

больше 7 лет назад

A same-origin policy violation allowing the theft of cross-origin URL ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-18493

больше 7 лет назад

A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-18493

больше 7 лет назад

A buffer overflow can occur in the Skia library during buffer offset c ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-18492

больше 7 лет назад

A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-18497

Limitations on the URIs allowed to WebExtensions by the browser.window ...

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18496

When the RSS Feed preview about:feeds page is framed within another page, it can be used in concert with scripted content for a clickjacking attack that confuses users into downloading and executing an executable file from a temporary directory. *Note: This issue only affects Windows operating systems. Other operating systems are not affected.*. This vulnerability affects Firefox < 64.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18496

When the RSS Feed preview about:feeds page is framed within another pa ...

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18495

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18495

WebExtension content scripts can be loaded into about: pages in some c ...

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18494

A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18494

A same-origin policy violation allowing the theft of cross-origin URL ...

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18493

A buffer overflow can occur in the Skia library during buffer offset calculations with hardware accelerated canvas 2D actions due to the use of 32-bit calculations instead of 64-bit. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 9.8
5%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-18493

A buffer overflow can occur in the Skia library during buffer offset c ...

CVSS3: 9.8
5%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-18492

A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 9.8
10%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться