Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-w8fm-f723-jm45

больше 3 лет назад

Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w7v9-gmfx-55cf

больше 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-w7p9-j7cw-wfpm

больше 3 лет назад

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

EPSS: Низкий
github логотип

GHSA-w7mj-jcq9-3g34

больше 3 лет назад

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-w757-mvqp-v98h

почти 4 года назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

EPSS: Низкий
github логотип

GHSA-w752-w9m4-4289

больше 3 лет назад

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w739-3fq5-fgvp

почти 4 года назад

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

EPSS: Средний
github логотип

GHSA-w6cr-qvrp-w86v

больше 3 лет назад

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-w694-6mxx-38mc

больше 1 года назад

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-w65j-fpvf-v9rw

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.

EPSS: Низкий
github логотип

GHSA-w5jf-q8p2-qgmx

больше 3 лет назад

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-w584-w92p-hx8h

почти 2 года назад

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w542-59hv-5363

больше 3 лет назад

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

EPSS: Средний
github логотип

GHSA-w4hq-q9jh-6r3x

больше 3 лет назад

If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w3xp-69rr-q6gw

больше 1 года назад

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-w3jv-r8w6-4m8j

почти 4 года назад

The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.

EPSS: Низкий
github логотип

GHSA-w3h2-4jrj-6mcc

больше 2 лет назад

A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. This could have lead to memory corruption or a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w3cw-f63h-9g34

около 2 месяцев назад

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w36j-5cvw-5rr3

больше 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-vxq2-h625-9q28

больше 3 лет назад

A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy objects. These properties should be explicitly unavailable to proxy objects. This vulnerability affects Firefox < 57.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w8fm-f723-jm45

Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w7v9-gmfx-55cf

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-w7p9-j7cw-wfpm

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

6%
Низкий
больше 3 лет назад
github логотип
GHSA-w7mj-jcq9-3g34

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w757-mvqp-v98h

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

0%
Низкий
почти 4 года назад
github логотип
GHSA-w752-w9m4-4289

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w739-3fq5-fgvp

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

26%
Средний
почти 4 года назад
github логотип
GHSA-w6cr-qvrp-w86v

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-w694-6mxx-38mc

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
1%
Низкий
больше 1 года назад
github логотип
GHSA-w65j-fpvf-v9rw

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-w5jf-q8p2-qgmx

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

CVSS3: 8.8
67%
Средний
больше 3 лет назад
github логотип
GHSA-w584-w92p-hx8h

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-w542-59hv-5363

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

13%
Средний
больше 3 лет назад
github логотип
GHSA-w4hq-q9jh-6r3x

If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-w3xp-69rr-q6gw

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

CVSS3: 8.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-w3jv-r8w6-4m8j

The CheckLoadURI function in Mozilla Firefox 1.8 lists the about: URI as a ChromeProtocol and can be loaded via JavaScript, which allows remote attackers to obtain sensitive information by querying the browser's session history.

1%
Низкий
почти 4 года назад
github логотип
GHSA-w3h2-4jrj-6mcc

A potential use-after-free vulnerability existed in SVG Images if the Refresh Driver was destroyed at an inopportune time. This could have lead to memory corruption or a potentially exploitable crash. *Note*: This advisory was added on December 13th, 2022 after discovering it was inadvertently left out of the original advisory. The fix was included in the original release of Firefox 106. This vulnerability affects Firefox < 106.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w3cw-f63h-9g34

Unicode RTLO characters could allow malicious websites to spoof filenames in the downloads UI for Firefox for iOS, potentially tricking users into saving files of an unexpected file type. This vulnerability affects Firefox for iOS < 144.0.

CVSS3: 6.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-w36j-5cvw-5rr3

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0, Firefox ESR 38.x before 38.8, and Firefox ESR 45.x before 45.1 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-vxq2-h625-9q28

A vulnerability where the security wrapper does not deny access to some exposed properties using the deprecated "_exposedProps_" mechanism on proxy objects. These properties should be explicitly unavailable to proxy objects. This vulnerability affects Firefox < 57.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу