Количество 15 398
Количество 15 398
openSUSE-SU-2020:0955-1
Security update for mozilla-nss
openSUSE-SU-2020:0953-1
Security update for mozilla-nss
openSUSE-SU-2018:0843-1
Security update for Mozilla Firefox
openSUSE-SU-2017:3272-1
Security update for MozillaFirefox
openSUSE-SU-2016:0489-1
Security update for MozillaFirefox
SUSE-SU-2024:1000-1
Security update for MozillaFirefox
SUSE-SU-2020:1850-1
Security update for mozilla-nss
RLSA-2024:0786
Moderate: nss security update
GHSA-xxh5-92qj-c4gh
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
GHSA-xx45-rh3m-ccvq
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
GHSA-xwpw-pxrm-39pm
When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.
GHSA-xwcx-vhr3-5qc7
Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.
GHSA-xvpg-g5h6-mqww
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
GHSA-xv7q-j96c-5r6v
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
GHSA-xv75-3499-88v3
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
GHSA-xrx5-vc96-3g46
Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.
GHSA-xrvj-239r-5xw7
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
GHSA-xrcj-j2px-vg49
layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
GHSA-xqh2-qprj-4679
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
GHSA-xq8c-wgh5-f4w9
Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2020:0955-1 Security update for mozilla-nss | 0% Низкий | больше 5 лет назад | ||
openSUSE-SU-2020:0953-1 Security update for mozilla-nss | 0% Низкий | больше 5 лет назад | ||
openSUSE-SU-2018:0843-1 Security update for Mozilla Firefox | 2% Низкий | больше 7 лет назад | ||
openSUSE-SU-2017:3272-1 Security update for MozillaFirefox | 1% Низкий | около 8 лет назад | ||
openSUSE-SU-2016:0489-1 Security update for MozillaFirefox | 1% Низкий | почти 10 лет назад | ||
SUSE-SU-2024:1000-1 Security update for MozillaFirefox | 1% Низкий | больше 1 года назад | ||
SUSE-SU-2020:1850-1 Security update for mozilla-nss | 0% Низкий | больше 5 лет назад | ||
RLSA-2024:0786 Moderate: nss security update | 0% Низкий | почти 2 года назад | ||
GHSA-xxh5-92qj-c4gh A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63. | CVSS3: 7.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xx45-rh3m-ccvq Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback. | 2% Низкий | больше 3 лет назад | ||
GHSA-xwpw-pxrm-39pm When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134. | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад | |
GHSA-xwcx-vhr3-5qc7 Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization. | 1% Низкий | больше 3 лет назад | ||
GHSA-xvpg-g5h6-mqww When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83. | 0% Низкий | больше 3 лет назад | ||
GHSA-xv7q-j96c-5r6v Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
GHSA-xv75-3499-88v3 The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xrx5-vc96-3g46 Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code. | 1% Низкий | больше 3 лет назад | ||
GHSA-xrvj-239r-5xw7 Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2. | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-xrcj-j2px-vg49 layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. | 18% Средний | больше 3 лет назад | ||
GHSA-xqh2-qprj-4679 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | 2% Низкий | больше 3 лет назад | ||
GHSA-xq8c-wgh5-f4w9 Integer underflow in the srtp_unprotect function in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу