Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Mozilla Firefox

Mozilla Firefoxсвободный браузер на движке Gecko

Релизный цикл, информация об уязвимостях

Продукт: Mozilla Firefox
Вендор: mozilla

График релизов

115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154202320242025202620272028

Релизные элементы

KBВерсияБилдДата доступности
138.0.4138.0.4
138.0.3138.0.3
138.0.1138.0.1
138.0138.0

Показывать по

Недавние уязвимости Mozilla Firefox

Количество 17 427

debian логотип

CVE-2018-12397

больше 7 лет назад

A WebExtension can request access to local files without the warning p ...

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2018-12396

больше 7 лет назад

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-12396

больше 7 лет назад

A vulnerability where a WebExtension can run content scripts in disall ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2018-12395

больше 7 лет назад

By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-12395

больше 7 лет назад

By rewriting the Host: request headers using the webRequest API, a Web ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-12393

больше 7 лет назад

A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-12393

больше 7 лет назад

A potential vulnerability was found in 32-bit builds where an integer ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-12392

больше 7 лет назад

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2018-12392

больше 7 лет назад

When manipulating user events in nested loops while opening a document ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2018-12391

больше 7 лет назад

During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2018-12397

A WebExtension can request access to local files without the warning p ...

CVSS3: 7.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12396

A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12396

A vulnerability where a WebExtension can run content scripts in disall ...

CVSS3: 6.5
2%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12395

By rewriting the Host: request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.

CVSS3: 7.5
3%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12395

By rewriting the Host: request headers using the webRequest API, a Web ...

CVSS3: 7.5
3%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12393

A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write. *Note: 64-bit builds are not vulnerable to this issue.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 7.5
4%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12393

A potential vulnerability was found in 32-bit builds where an integer ...

CVSS3: 7.5
4%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12392

When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 9.8
3%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-12392

When manipulating user events in nested loops while opening a document ...

CVSS3: 9.8
3%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-12391

During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access. *Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.*. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

CVSS3: 8.8
2%
Низкий
больше 7 лет назад

Уязвимостей на страницу


Поделиться