Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17 208

Количество 17 208

github логотип

GHSA-w96m-wgv7-3r86

почти 3 года назад

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w92w-fc6m-j79x

около 4 лет назад

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w8qx-wh3f-f42p

около 4 лет назад

Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

EPSS: Низкий
github логотип

GHSA-w8ph-2788-7wg9

около 4 лет назад

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

EPSS: Низкий
github логотип

GHSA-w8p9-p5cr-4q8f

около 4 лет назад

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-w8fm-f723-jm45

около 4 лет назад

Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w7v9-gmfx-55cf

около 4 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-w7p9-j7cw-wfpm

около 4 лет назад

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

EPSS: Низкий
github логотип

GHSA-w7mj-jcq9-3g34

около 4 лет назад

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-w757-mvqp-v98h

около 4 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

EPSS: Низкий
github логотип

GHSA-w752-w9m4-4289

около 4 лет назад

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w739-3fq5-fgvp

около 4 лет назад

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

EPSS: Низкий
github логотип

GHSA-w6cr-qvrp-w86v

около 4 лет назад

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-w694-6mxx-38mc

около 2 лет назад

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-w65j-fpvf-v9rw

около 4 лет назад

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.

EPSS: Низкий
github логотип

GHSA-w5jf-q8p2-qgmx

около 4 лет назад

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

CVSS3: 8.8
EPSS: Средний
github логотип

GHSA-w584-w92p-hx8h

больше 2 лет назад

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w542-59hv-5363

около 4 лет назад

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

EPSS: Низкий
github логотип

GHSA-w4hq-q9jh-6r3x

около 4 лет назад

If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-w3xp-69rr-q6gw

почти 2 года назад

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-w96m-wgv7-3r86

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116.

CVSS3: 7.5
1%
Низкий
почти 3 года назад
github логотип
GHSA-w92w-fc6m-j79x

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

CVSS3: 8.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-w8qx-wh3f-f42p

Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

1%
Низкий
около 4 лет назад
github логотип
GHSA-w8ph-2788-7wg9

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

1%
Низкий
около 4 лет назад
github логотип
GHSA-w8p9-p5cr-4q8f

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-w8fm-f723-jm45

Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-w7v9-gmfx-55cf

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

5%
Низкий
около 4 лет назад
github логотип
GHSA-w7p9-j7cw-wfpm

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

2%
Низкий
около 4 лет назад
github логотип
GHSA-w7mj-jcq9-3g34

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-w757-mvqp-v98h

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

2%
Низкий
около 4 лет назад
github логотип
GHSA-w752-w9m4-4289

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
2%
Низкий
около 4 лет назад
github логотип
GHSA-w739-3fq5-fgvp

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

3%
Низкий
около 4 лет назад
github логотип
GHSA-w6cr-qvrp-w86v

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
0%
Низкий
около 4 лет назад
github логотип
GHSA-w694-6mxx-38mc

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
1%
Низкий
около 2 лет назад
github логотип
GHSA-w65j-fpvf-v9rw

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.

1%
Низкий
около 4 лет назад
github логотип
GHSA-w5jf-q8p2-qgmx

Heap-based buffer overflow in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via foreign-context HTML5 fragments, as demonstrated by fragments within an SVG element.

CVSS3: 8.8
24%
Средний
около 4 лет назад
github логотип
GHSA-w584-w92p-hx8h

If an insecure element was added to a page after a delay, Firefox would not replace the secure icon with a mixed content security status This vulnerability affects Firefox for iOS < 124.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-w542-59hv-5363

The session restore feature in Mozilla Firefox 3.x before 3.0.4 and 2.x before 2.0.0.18 allows remote attackers to violate the same origin policy to conduct cross-site scripting (XSS) attacks and execute arbitrary JavaScript with chrome privileges via unknown vectors.

3%
Низкий
около 4 лет назад
github логотип
GHSA-w4hq-q9jh-6r3x

If Media Capture and Streams API permission is requested from documents with "data:" or "blob:" URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown protocol" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 59.

CVSS3: 5.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-w3xp-69rr-q6gw

A select option could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. *This issue only affects Android versions of Firefox.* This vulnerability affects Firefox < 129.

CVSS3: 8.1
0%
Низкий
почти 2 года назад

Уязвимостей на страницу