Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-px89-65ch-24x4

больше 3 лет назад

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-pwqf-hfj5-2rrc

больше 3 лет назад

Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.

EPSS: Низкий
github логотип

GHSA-pwq5-w788-7w28

больше 3 лет назад

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-pw85-c3xj-rm6m

почти 4 года назад

Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a "dangling pointer vulnerability."

EPSS: Низкий
github логотип

GHSA-pvxc-5v6m-8cm2

3 месяца назад

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pvg5-mc56-6fv7

почти 2 года назад

Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-pv8w-m2qh-gvj6

больше 3 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-prww-hcp7-652r

около 3 лет назад

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-prc6-qwc4-rr5x

почти 4 года назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

EPSS: Низкий
github логотип

GHSA-pqvw-c6xw-gpp5

больше 3 лет назад

Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-pq8c-jr49-74hj

больше 3 лет назад

When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerability affects Firefox < 72.

EPSS: Низкий
github логотип

GHSA-pq5r-x8h8-c67r

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-pphh-8m7v-77cf

больше 3 лет назад

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.

EPSS: Низкий
github логотип

GHSA-pp7m-q233-vq86

около 3 лет назад

Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-pp62-p6gv-gqgj

больше 3 лет назад

Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.

EPSS: Низкий
github логотип

GHSA-pp5v-ch72-95w4

больше 3 лет назад

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-pp2c-fw86-vf75

больше 3 лет назад

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-pmcc-4v53-j538

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 72.

EPSS: Низкий
github логотип

GHSA-pm7g-mpjq-33gr

больше 1 года назад

Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-pjg4-cx24-6mjc

8 месяцев назад

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-px89-65ch-24x4

The WebExtension sandbox feature in browser/components/extensions/ext-tabs.js in Mozilla Firefox before 46.0 does not properly restrict principal inheritance during chrome.tabs.create and chrome.tabs.update API calls, which allows remote attackers to conduct Universal XSS (UXSS) attacks via a crafted extension that accesses a (1) javascript: or (2) data: URL.

CVSS3: 5.4
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pwqf-hfj5-2rrc

Buffer overflow in the vp9_init_context_buffers function in libvpx, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3, allows remote attackers to execute arbitrary code via a crafted VP9 file.

8%
Низкий
больше 3 лет назад
github логотип
GHSA-pwq5-w788-7w28

A vulnerability exists where it possible to force Network Security Services (NSS) to sign CertificateVerify with PKCS#1 v1.5 signatures when those are the only ones advertised by server in CertificateRequest in TLS 1.3. PKCS#1 v1.5 signatures should not be used for TLS 1.3 messages. This vulnerability affects Firefox < 68.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pw85-c3xj-rm6m

Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.3, does not properly manage pointers for the columns (aka TreeColumns) of a XUL tree element, which allows remote attackers to execute arbitrary code via a crafted HTML document, related to a "dangling pointer vulnerability."

5%
Низкий
почти 4 года назад
github логотип
GHSA-pvxc-5v6m-8cm2

Incorrect boundary conditions in the JavaScript: WebAssembly component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.

CVSS3: 7.5
0%
Низкий
3 месяца назад
github логотип
GHSA-pvg5-mc56-6fv7

Data was not properly sanitized when decoding a QUIC ACK frame; this could have led to unrestricted memory consumption and a crash. This vulnerability affects Firefox < 124.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-pv8w-m2qh-gvj6

Mozilla developers and community members reported memory safety bugs present in Firefox 64. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 65.

CVSS3: 9.8
5%
Низкий
больше 3 лет назад
github логотип
GHSA-prww-hcp7-652r

ASN.1 parsing of an indefinite SEQUENCE inside an indefinite GROUP could have resulted in the parser accepting malformed ASN.1. This vulnerability affects Firefox < 102.

CVSS3: 9.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-prc6-qwc4-rr5x

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0, when UTF-7 document content is rendered directly in UTF-7, allows remote attackers to inject arbitrary web script or HTML via a gopher URI that uses single quote characters to delimit a literal string within an XSS sequence, a related issue to CVE-2007-5415.

0%
Низкий
почти 4 года назад
github логотип
GHSA-pqvw-c6xw-gpp5

Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-pq8c-jr49-74hj

When in Private Browsing Mode on Windows 10, the Windows keyboard may retain word suggestions to improve the accuracy of the keyboard. This vulnerability affects Firefox < 72.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-pq5r-x8h8-c67r

Mozilla developers reported memory safety bugs present in Firefox 84. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 85.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-pphh-8m7v-77cf

The about:crashcontent and about:crashparent pages can be triggered by web content. These pages are used to crash the loaded page or the browser for test purposes. This issue allows for a non-persistent denial of service (DOS) attack by a malicious site which links to these pages. This vulnerability affects Firefox < 64.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-pp7m-q233-vq86

Under certain circumstances, a JavaScript alert (or prompt) could have been shown while another website was displayed underneath it. This could have been abused to trick the user. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-pp62-p6gv-gqgj

Mozilla Firefox before 31.0 does not properly restrict use of drag-and-drop events to spoof customization events, which allows remote attackers to alter the placement of UI icons via crafted JavaScript code that is encountered during (1) page, (2) panel, or (3) toolbar customization.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-pp5v-ch72-95w4

WebExtensions bundled with embedded experiments were not correctly checked for proper authorization. This allowed a malicious WebExtension to gain full browser permissions. This vulnerability affects Firefox ESR < 60.1 and Firefox < 61.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-pp2c-fw86-vf75

Cross-origin images can be read from a canvas element in violation of the same-origin policy using the transferFromImageBitmap method. *Note: This only affects Firefox 65. Previous versions are unaffected.*. This vulnerability affects Firefox < 65.0.1.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-pmcc-4v53-j538

Mozilla developers reported memory safety bugs present in Firefox 71. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 72.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-pm7g-mpjq-33gr

Memory safety bugs present in Firefox 129. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 130.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-pjg4-cx24-6mjc

Error handling for script execution was incorrectly isolated from web content, which could have allowed cross-origin leak attacks. This vulnerability affects Firefox < 139, Firefox ESR < 115.24, and Firefox ESR < 128.11.

CVSS3: 4.3
0%
Низкий
8 месяцев назад

Уязвимостей на страницу