Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-rf5c-p2xm-2r64

около 3 лет назад

Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 100.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rcq3-vgfc-jm9v

больше 3 лет назад

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.

EPSS: Низкий
github логотип

GHSA-rcj2-hjg7-xj8p

больше 3 лет назад

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-r9m2-q2gr-6g6w

больше 3 лет назад

Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.

EPSS: Низкий
github логотип

GHSA-r97x-58x3-7qgg

больше 3 лет назад

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-r8rg-hmw6-929h

больше 3 лет назад

Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the Firefox profile after the mode is exited. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-r8fq-xfh5-mvgx

больше 3 лет назад

OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

EPSS: Низкий
github логотип

GHSA-r848-g58f-v3hw

больше 3 лет назад

When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.

EPSS: Низкий
github логотип

GHSA-r7fp-wxjp-2rf9

около 3 лет назад

The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r75w-mj28-6x5x

больше 3 лет назад

When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 72.

EPSS: Низкий
github логотип

GHSA-r745-vx44-pc94

больше 3 лет назад

Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal information not meant to be seen by web content. This vulnerability affects Firefox < 51.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r6xw-ww9g-m6wg

больше 3 лет назад

When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.

EPSS: Низкий
github логотип

GHSA-r6ww-vw3x-xp48

почти 4 года назад

Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.

EPSS: Низкий
github логотип

GHSA-r6wj-xmgr-mg33

больше 1 года назад

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-r6p5-8pxg-2vcp

около 4 лет назад

When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web Extension should have access to. This was fixed to provide the pre-redirect URL. This is related to CVE-2021-43532 but in the context of Web Extensions. This vulnerability affects Firefox < 94.

EPSS: Низкий
github логотип

GHSA-r5q3-cfrm-hqph

больше 3 лет назад

On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as the dialog's location, spoofing of the origin of the modal dialog from the user view. Note: This attack only affects installations with e10 multiprocess turned off. Installations with e10s turned on do not support the modal dialog functionality. This vulnerability affects Firefox < 56.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-r5m5-v5v5-wq3f

больше 3 лет назад

Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-r56v-99h2-76vh

больше 3 лет назад

Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

EPSS: Низкий
github логотип

GHSA-r55c-w846-xc87

больше 3 лет назад

A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-of-bounds write. This vulnerability affects Firefox < 58.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-r52r-p4hh-9m3j

почти 4 года назад

libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-rf5c-p2xm-2r64

Mozilla developers Gabriele Svelto, Randell Jesup and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 99. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 100.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-rcq3-vgfc-jm9v

If a valid external protocol handler was referenced in an image tag, the resulting broken image size could be distinguished from a broken image size of a non-existent protocol handler. This allowed an attacker to successfully probe whether an external protocol handler was registered. This vulnerability affects Firefox < 82.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-rcj2-hjg7-xj8p

When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-r9m2-q2gr-6g6w

Mozilla Firefox before 21.0 does not properly implement the INPUT element, which allows remote attackers to obtain the full pathname via a crafted web site.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-r97x-58x3-7qgg

Use-after-free while manipulating the "navigator" object within WebVR. Note: WebVR is not currently enabled by default. This vulnerability affects Firefox < 50.1.

CVSS3: 8.1
2%
Низкий
больше 3 лет назад
github логотип
GHSA-r8rg-hmw6-929h

Private browsing mode leaves metadata information, such as URLs, for sites visited in "browser.db" and "browser.db-wal" files within the Firefox profile after the mode is exited. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

CVSS3: 3.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-r8fq-xfh5-mvgx

OneCRL was non-functional in the new Firefox for Android due to a missing service initialization. This could result in a failure to enforce some certificate revocations. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r848-g58f-v3hw

When styling and rendering an oversized `<select>` element, Firefox did not apply correct clipping which allowed an attacker to paint over the user interface. This vulnerability affects Firefox < 89.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r7fp-wxjp-2rf9

The Performance API did not properly hide the fact whether a request cross-origin resource has observed redirects. This vulnerability affects Firefox < 100.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-r75w-mj28-6x5x

When Python was installed on Windows, a python file being served with the MIME type of text/plain could be executed by Python instead of being opened as a text file when the Open option was selected upon download. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 72.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r745-vx44-pc94

Feed preview for RSS feeds can be used to capture errors and exceptions generated by privileged content, allowing for the exposure of internal information not meant to be seen by web content. This vulnerability affects Firefox < 51.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-r6xw-ww9g-m6wg

When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the keyboard dictionary. This vulnerability affects Firefox for Android < 80.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r6ww-vw3x-xp48

Mozilla Firefox 3.6a1, 3.5.3, 3.5.2, and earlier 3.5.x versions, and 3.0.14 and earlier 2.x and 3.x versions, on Linux uses a predictable /tmp pathname for files selected from the Downloads window, which allows local users to replace an arbitrary downloaded file by placing a file in a /tmp location before the download occurs, related to the Download Manager component. NOTE: some of these details are obtained from third party information.

0%
Низкий
почти 4 года назад
github логотип
GHSA-r6wj-xmgr-mg33

Memory safety bugs present in Firefox 125. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 126.

CVSS3: 9.8
0%
Низкий
больше 1 года назад
github логотип
GHSA-r6p5-8pxg-2vcp

When a user loaded a Web Extensions context menu, the Web Extension could access the post-redirect URL of the element clicked. If the Web Extension lacked the WebRequest permission for the hosts involved in the redirect, this would be a same-origin-violation leaking data the Web Extension should have access to. This was fixed to provide the pre-redirect URL. This is related to CVE-2021-43532 but in the context of Web Extensions. This vulnerability affects Firefox < 94.

0%
Низкий
около 4 лет назад
github логотип
GHSA-r5q3-cfrm-hqph

On pages containing an iframe, the "data:" protocol can be used to create a modal dialog through Javascript that will have an arbitrary domains as the dialog's location, spoofing of the origin of the modal dialog from the user view. Note: This attack only affects installations with e10 multiprocess turned off. Installations with e10s turned on do not support the modal dialog functionality. This vulnerability affects Firefox < 56.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-r5m5-v5v5-wq3f

Mozilla Firefox before 44.0 stores cookies with names containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-7208.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-r56v-99h2-76vh

Navigations through the Android-specific `intent` URL scheme could have been misused to escape iframe sandbox. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-r55c-w846-xc87

A potential integer overflow in the "DoCrypt" function of WebCrypto was identified. If a means was found of exploiting it, it could result in an out-of-bounds write. This vulnerability affects Firefox < 58.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-r52r-p4hh-9m3j

libvorbis before r16182, as used in Mozilla Firefox 3.5.x before 3.5.2 and other products, allows context-dependent attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a crafted .ogg file.

2%
Низкий
почти 4 года назад

Уязвимостей на страницу