Количество 17 208
Количество 17 208
openSUSE-SU-2020:0955-1
Security update for mozilla-nss
openSUSE-SU-2020:0953-1
Security update for mozilla-nss
openSUSE-SU-2018:0843-1
Security update for Mozilla Firefox
openSUSE-SU-2017:3272-1
Security update for MozillaFirefox
openSUSE-SU-2016:0489-1
Security update for MozillaFirefox
SUSE-SU-2024:1000-1
Security update for MozillaFirefox
SUSE-SU-2020:1850-1
Security update for mozilla-nss
RLSA-2024:0786
Moderate: nss security update
GHSA-xxh5-92qj-c4gh
A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63.
GHSA-xx45-rh3m-ccvq
Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback.
GHSA-xwpw-pxrm-39pm
When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.
GHSA-xwcx-vhr3-5qc7
Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization.
GHSA-xvpg-g5h6-mqww
When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.
GHSA-xv7q-j96c-5r6v
Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.
GHSA-xv75-3499-88v3
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
GHSA-xrx5-vc96-3g46
Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code.
GHSA-xrvj-239r-5xw7
Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2.
GHSA-xrr7-cwrw-39vw
Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13.
GHSA-xrcj-j2px-vg49
layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors.
GHSA-xr3f-844g-572f
Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
openSUSE-SU-2020:0955-1 Security update for mozilla-nss | 0% Низкий | около 6 лет назад | ||
openSUSE-SU-2020:0953-1 Security update for mozilla-nss | 0% Низкий | около 6 лет назад | ||
openSUSE-SU-2018:0843-1 Security update for Mozilla Firefox | 3% Низкий | больше 8 лет назад | ||
openSUSE-SU-2017:3272-1 Security update for MozillaFirefox | 3% Низкий | больше 8 лет назад | ||
openSUSE-SU-2016:0489-1 Security update for MozillaFirefox | 2% Низкий | больше 10 лет назад | ||
SUSE-SU-2024:1000-1 Security update for MozillaFirefox | 5% Низкий | больше 2 лет назад | ||
SUSE-SU-2020:1850-1 Security update for mozilla-nss | 0% Низкий | около 6 лет назад | ||
RLSA-2024:0786 Moderate: nss security update | 1% Низкий | больше 2 лет назад | ||
GHSA-xxh5-92qj-c4gh A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened. This vulnerability affects Firefox ESR < 60.3 and Firefox < 63. | CVSS3: 7.1 | 0% Низкий | около 4 лет назад | |
GHSA-xx45-rh3m-ccvq Buffer overflow in libstagefright in Mozilla Firefox before 36.0 allows remote attackers to execute arbitrary code via a crafted MP4 video that is improperly handled during playback. | 6% Низкий | около 4 лет назад | ||
GHSA-xwpw-pxrm-39pm When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-xwcx-vhr3-5qc7 Race condition in the AsyncPaintWaitEvent::AsyncPaintWaitEvent function in Mozilla Firefox before 37.0.2 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via a crafted plugin that does not properly complete initialization. | 3% Низкий | около 4 лет назад | ||
GHSA-xvpg-g5h6-mqww When a user downloaded a file in Firefox for Android, if a cookie is set, it would have been re-sent during a subsequent file download operation on the same domain, regardless of whether the original and subsequent request were in private and non-private browsing modes. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83. | 1% Низкий | около 4 лет назад | ||
GHSA-xv7q-j96c-5r6v Script elements loading cross-origin resources generated load and error events which leaked information enabling XS-Leaks attacks. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-xv75-3499-88v3 The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive. | CVSS3: 8.8 | 3% Низкий | около 4 лет назад | |
GHSA-xrx5-vc96-3g46 Firefox before 1.0 allows the user to store a (1) javascript: or (2) data: URLs as a Livefeed bookmark, then executes it in the security context of the currently loaded page when the user later accesses the bookmark, which could allow remote attackers to execute arbitrary code. | 2% Низкий | около 4 лет назад | ||
GHSA-xrvj-239r-5xw7 Web content could access information in the HTTP cache if e10s is disabled. This can reveal some visited URLs and the contents of those pages. This issue affects Firefox 48 and 49. This vulnerability affects Firefox < 49.0.2. | CVSS3: 5.9 | 2% Низкий | около 4 лет назад | |
GHSA-xrr7-cwrw-39vw Memory safety bugs present in Firefox ESR 140.12 and Firefox 152. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 153 and Firefox ESR 140.13. | CVSS3: 9.8 | 0% Низкий | 9 дней назад | |
GHSA-xrcj-j2px-vg49 layout/base/nsCSSFrameConstructor.cpp in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 does not properly handle first-letter frames, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. | 11% Средний | около 4 лет назад | ||
GHSA-xr3f-844g-572f Incorrect boundary conditions in the Graphics: Canvas2D component. This vulnerability affects Firefox < 149, Firefox ESR < 115.34, and Firefox ESR < 140.9. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад |
Уязвимостей на страницу