Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2018-12402

больше 7 лет назад

The internal WebBrowserPersist code does not use correct origin contex ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-12401

больше 7 лет назад

Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-12401

больше 7 лет назад

Some special resource URIs will cause a non-exploitable crash if loade ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-12400

больше 7 лет назад

In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2018-12400

больше 7 лет назад

In private browsing mode on Firefox for Android, favicons are cached i ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-12399

больше 7 лет назад

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2018-12399

больше 7 лет назад

When a new protocol handler is registered, the API accepts a title arg ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2018-12398

больше 7 лет назад

By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-12398

больше 7 лет назад

By using the reflected URL in some special resource URIs, such as chro ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-12397

больше 7 лет назад

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-12402

The internal WebBrowserPersist code does not use correct origin contex ...

CVSS3: 6.5
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12401

Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks. This vulnerability affects Firefox < 63.

CVSS3: 7.5
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12401

Some special resource URIs will cause a non-exploitable crash if loade ...

CVSS3: 7.5
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12400

In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63.

CVSS3: 5.3
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12400

In private browsing mode on Firefox for Android, favicons are cached i ...

CVSS3: 5.3
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12399

When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have. This vulnerability affects Firefox < 63.

CVSS3: 4.3
1%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12399

When a new protocol handler is registered, the API accepts a title arg ...

CVSS3: 4.3
1%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12398

By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP). This vulnerability affects Firefox < 63.

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12398

By using the reflected URL in some special resource URIs, such as chro ...

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12397

A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.1
0%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться