Количество 17 673
Количество 17 673
openSUSE-SU-2020:0955-1
Security update for mozilla-nss
openSUSE-SU-2020:0953-1
Security update for mozilla-nss
openSUSE-SU-2018:0843-1
Security update for Mozilla Firefox
openSUSE-SU-2017:3272-1
Security update for MozillaFirefox
openSUSE-SU-2016:0489-1
Security update for MozillaFirefox
SUSE-SU-2024:1000-1
Security update for MozillaFirefox
SUSE-SU-2020:1850-1
Security update for mozilla-nss
RLSA-2024:0786
Moderate: nss security update
GHSA-xxh5-92qj-c4gh
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
GHSA-xx45-rh3m-ccvq
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
GHSA-xwpw-pxrm-39pm
When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.
GHSA-xwcx-vhr3-5qc7
Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.
GHSA-xv7q-j96c-5r6v
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
GHSA-xv75-3499-88v3
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
GHSA-xrx5-vc96-3g46
Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.
GHSA-xrvj-239r-5xw7
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
GHSA-xrr7-cwrw-39vw
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
GHSA-xrcj-j2px-vg49
layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
GHSA-xr3f-844g-572f
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.
GHSA-xqh2-qprj-4679
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2020:0955-1 Security update for mozilla-nss | 0% Низкий | около 6 лет назад | ||
openSUSE-SU-2020:0953-1 Security update for mozilla-nss | 0% Низкий | около 6 лет назад | ||
openSUSE-SU-2018:0843-1 Security update for Mozilla Firefox | 3% Низкий | больше 8 лет назад | ||
openSUSE-SU-2017:3272-1 Security update for MozillaFirefox | 3% Низкий | почти 9 лет назад | ||
openSUSE-SU-2016:0489-1 Security update for MozillaFirefox | 2% Низкий | больше 10 лет назад | ||
SUSE-SU-2024:1000-1 Security update for MozillaFirefox | 5% Низкий | больше 2 лет назад | ||
SUSE-SU-2020:1850-1 Security update for mozilla-nss | 0% Низкий | около 6 лет назад | ||
RLSA-2024:0786 Moderate: nss security update | 1% Низкий | больше 2 лет назад | ||
GHSA-xxh5-92qj-c4gh A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63. | CVSS3: 7.1 | 0% Низкий | больше 4 лет назад | |
GHSA-xx45-rh3m-ccvq Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback. | 6% Низкий | больше 4 лет назад | ||
GHSA-xwpw-pxrm-39pm When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-xwcx-vhr3-5qc7 Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization. | 3% Низкий | больше 4 лет назад | ||
GHSA-xv7q-j96c-5r6v Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-xv75-3499-88v3 The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive. | CVSS3: 8.8 | 3% Низкий | больше 4 лет назад | |
GHSA-xrx5-vc96-3g46 Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code. | 2% Низкий | больше 4 лет назад | ||
GHSA-xrvj-239r-5xw7 Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2. | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
GHSA-xrr7-cwrw-39vw Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
GHSA-xrcj-j2px-vg49 layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. | 11% Средний | больше 4 лет назад | ||
GHSA-xr3f-844g-572f Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
GHSA-xqh2-qprj-4679 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | 6% Низкий | больше 4 лет назад |
Уязвимостей на страницу