Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2018-18492

больше 7 лет назад

A use-after-free vulnerability can occur after deleting a selection el ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-12407

больше 7 лет назад

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-12407

больше 7 лет назад

A buffer overflow occurs when drawing and validating elements with the ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-12406

больше 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 64.

CVSS3: 8.8
EPSS: Низкий
debian логотип

CVE-2018-12406

больше 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
EPSS: Низкий
nvd логотип

CVE-2018-12405

больше 7 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-12405

больше 7 лет назад

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-12403

больше 7 лет назад

If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-12403

больше 7 лет назад

If a site is loaded over a HTTPS connection but loads a favicon resour ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-12402

больше 7 лет назад

The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they can convince the visitor to save the complete web page. Similarly, SameSite cookies are sent on cross-origin requests when the "Save Page As..." menu item is selected to save a page, which can result in saving the wrong version of resources based on those cookies. This vulnerability affects Firefox < 63.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-18492

A use-after-free vulnerability can occur after deleting a selection el ...

CVSS3: 9.8
10%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12407

A buffer overflow occurs when drawing and validating elements with the ANGLE graphics library, used for WebGL content, when working with the VertexBuffer11 module. This results in a potentially exploitable crash. This vulnerability affects Firefox < 64.

CVSS3: 9.8
3%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12407

A buffer overflow occurs when drawing and validating elements with the ...

CVSS3: 9.8
3%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12406

Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 64.

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12406

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 8.8
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12405

Mozilla developers and community members reported memory safety bugs present in Firefox 63 and Firefox ESR 60.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 60.4, Firefox ESR < 60.4, and Firefox < 64.

CVSS3: 9.8
3%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12405

Mozilla developers and community members reported memory safety bugs p ...

CVSS3: 9.8
3%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12403

If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63.

CVSS3: 5.3
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12403

If a site is loaded over a HTTPS connection but loads a favicon resour ...

CVSS3: 5.3
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12402

The internal WebBrowserPersist code does not use correct origin context for a resource being saved. This manifests when sub-resources are loaded as part of "Save Page As..." functionality. For example, a malicious page could recover a visitor's Windows username and NTLM hash by including resources otherwise unreachable to the malicious page, if they can convince the visitor to save the complete web page. Similarly, SameSite cookies are sent on cross-origin requests when the "Save Page As..." menu item is selected to save a page, which can result in saving the wrong version of resources based on those cookies. This vulnerability affects Firefox < 63.

CVSS3: 6.5
1%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться