Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-xq4h-hmq6-ghrv

больше 3 лет назад

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.

EPSS: Низкий
github логотип

GHSA-xp69-qpvf-q5f5

больше 3 лет назад

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-xp2p-6mv7-gcrx

больше 3 лет назад

When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xp29-g429-j593

больше 3 лет назад

Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

EPSS: Низкий
github логотип

GHSA-xmm2-x5jc-rvmh

больше 1 года назад

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xmh3-55xm-hpg9

больше 3 лет назад

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-xmc5-26p9-v4x6

больше 3 лет назад

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xj5m-432r-gpqm

больше 3 лет назад

The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

EPSS: Низкий
github логотип

GHSA-xhfv-25pm-fp3g

больше 3 лет назад

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

EPSS: Низкий
github логотип

GHSA-xh4q-pv2r-82c7

почти 4 года назад

Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a large number of IMG elements in which the SRC attribute is a mailto URI. NOTE: another researcher found that the web page caused a temporary browser slowdown instead of a crash.

EPSS: Низкий
github логотип

GHSA-xgvx-m8xh-737m

больше 3 лет назад

The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-xg8q-ggjx-6hx2

8 месяцев назад

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-xg4r-c4j2-fcj4

больше 3 лет назад

Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability affects Firefox < 57.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xfhf-q7xr-xpw6

больше 3 лет назад

A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buffer, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.1.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xf5w-2jf5-86c8

больше 3 лет назад

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xf23-357c-2vmh

больше 3 лет назад

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

EPSS: Низкий
github логотип

GHSA-xcgp-vxv9-g7g2

больше 3 лет назад

The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.

EPSS: Низкий
github логотип

GHSA-xc8j-mr73-m6wv

почти 2 года назад

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x9h6-qwxm-528g

11 месяцев назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-x945-jm33-f3qv

почти 2 года назад

Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xq4h-hmq6-ghrv

Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xp69-qpvf-q5f5

Necko can access a child on the wrong thread during UDP connections, resulting in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 68.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xp2p-6mv7-gcrx

When "%2F" was present in a manifest URL, Firefox's AppCache behavior may have become confused and allowed a manifest to be served from a subdirectory. This could cause the appcache to be used to service requests for the top level directory. This vulnerability affects Firefox < 78.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xp29-g429-j593

Mozilla Firefox before 37.0 does not require an HTTPS session for lightweight theme add-on installations, which allows man-in-the-middle attackers to bypass an intended user-confirmation requirement by deploying a crafted web site and conducting a DNS spoofing attack against a mozilla.org subdomain.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xmm2-x5jc-rvmh

Long pressing on a download link could potentially provide a means for cross-site scripting This vulnerability affects Firefox for iOS < 129.

CVSS3: 6.1
1%
Низкий
больше 1 года назад
github логотип
GHSA-xmh3-55xm-hpg9

An attack can use a blob URL and script to spoof an arbitrary addressbar URL prefaced by "blob:" as the protocol, leading to user confusion and further spoofing attacks. This vulnerability affects Firefox < 52.

CVSS3: 5.3
29%
Средний
больше 3 лет назад
github логотип
GHSA-xmc5-26p9-v4x6

WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xj5m-432r-gpqm

The fetch API implementation in Mozilla Firefox before 41.0.2 does not restrict access to the HTTP response body in certain situations where user credentials are supplied but the CORS cross-origin request algorithm is improperly followed, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xhfv-25pm-fp3g

Mozilla Firefox before 39.0 on OS X includes native key press information during the logging of crashes, which allows remote attackers to obtain sensitive information by leveraging access to a crash-reporting data stream.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xh4q-pv2r-82c7

Mozilla Firefox 1.5.0.3 allows remote attackers to cause a denial of service via a web page with a large number of IMG elements in which the SRC attribute is a mailto URI. NOTE: another researcher found that the web page caused a temporary browser slowdown instead of a crash.

1%
Низкий
почти 4 года назад
github логотип
GHSA-xgvx-m8xh-737m

The DOMParser API did not properly process '<noscript>' elements for escaping. This could be used as an mXSS vector to bypass an HTML Sanitizer. This vulnerability affects Firefox < 86.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-xg8q-ggjx-6hx2

A clickjacking vulnerability could have been used to trick a user into leaking saved payment card details to a malicious page. This vulnerability affects Firefox < 139 and Firefox ESR < 128.11.

CVSS3: 5.4
0%
Низкий
8 месяцев назад
github логотип
GHSA-xg4r-c4j2-fcj4

Punycode format text will be displayed for entire qualified international domain names in some instances when a sub-domain triggers the punycode display instead of the primary domain being displayed in native script and the sub-domain only displaying as punycode. This could be used for limited spoofing attacks due to user confusion. This vulnerability affects Firefox < 57.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xfhf-q7xr-xpw6

A buffer overflow in SkiaGl caused when a GrGLBuffer is truncated during allocation. Later writers will overflow the buffer, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.1.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-xf5w-2jf5-86c8

WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-xf23-357c-2vmh

Mozilla Firefox before 35.0 on Windows allows remote attackers to bypass the Gecko Media Plugin (GMP) sandbox protection mechanism by leveraging access to the GMP process, as demonstrated by the OpenH264 plugin's process.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-xcgp-vxv9-g7g2

The getUserMedia permission implementation in Mozilla Firefox before 22.0 references the URL of a top-level document instead of the URL of a specific page, which makes it easier for remote attackers to trick users into permitting camera or microphone access via a crafted web site that uses IFRAME elements.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-xc8j-mr73-m6wv

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

CVSS3: 6.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-x9h6-qwxm-528g

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
0%
Низкий
11 месяцев назад
github логотип
GHSA-x945-jm33-f3qv

Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.

CVSS3: 4.3
0%
Низкий
почти 2 года назад

Уязвимостей на страницу