Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-p7gv-qvfm-xf29

почти 4 года назад

Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) file:/// URI.

EPSS: Низкий
github логотип

GHSA-p6rv-hx36-fjv2

больше 3 лет назад

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

EPSS: Средний
github логотип

GHSA-p6j5-jrmm-j3w6

почти 2 года назад

A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p6h6-f79f-g6cp

почти 4 года назад

ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service (application crash) via a crafted reply to an unspecified listing command, related to "reading from invalid pointer."

EPSS: Низкий
github логотип

GHSA-p5jc-239c-pvvf

12 месяцев назад

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p5hw-4fxj-g4x6

больше 1 года назад

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-p5g9-gchg-7wgv

больше 3 лет назад

js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.

EPSS: Низкий
github логотип

GHSA-p5g7-573c-m74m

8 месяцев назад

Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-p5fj-7pgr-xv7v

почти 4 года назад

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

EPSS: Высокий
github логотип

GHSA-p5f8-m753-hvgf

около 3 лет назад

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-p549-c3cg-f4qm

10 месяцев назад

By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-p52p-vjgp-j832

больше 3 лет назад

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-p4qw-x342-xjwx

почти 4 года назад

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.

EPSS: Средний
github логотип

GHSA-p397-mrp5-f5r7

больше 2 лет назад

Mozilla developers and community members Calixte Denizet, Gabriele Svelto, Andrew McCreight, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-p364-qwq2-fh4v

почти 4 года назад

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.

EPSS: Низкий
github логотип

GHSA-p2g2-wp3h-q672

3 месяца назад

Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and Firefox ESR < 115.30.

CVSS3: 3.4
EPSS: Низкий
github логотип

GHSA-p2f5-76jq-f5vv

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 89.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-p26w-gphp-32x2

больше 3 лет назад

Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mxw3-h8f2-qrw5

больше 3 лет назад

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-mxfw-955c-c6f5

почти 4 года назад

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-p7gv-qvfm-xf29

Mozilla Firefox 2.0.0.9 allows remote attackers to cause a denial of service (CPU consumption and crash) via an iframe with Javascript that sets the document.location to contain a leading NULL byte (\x00) and a (1) res://, (2) about:config, or (3) file:/// URI.

1%
Низкий
почти 4 года назад
github логотип
GHSA-p6rv-hx36-fjv2

Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

15%
Средний
больше 3 лет назад
github логотип
GHSA-p6j5-jrmm-j3w6

A use-after-free could result if a JavaScript realm was in the process of being initialized when a garbage collection started. This vulnerability affects Firefox < 125.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-p6h6-f79f-g6cp

ParseFTPList.cpp in Mozilla Firefox 2.0.0.7 allows remote FTP servers to cause a denial of service (application crash) via a crafted reply to an unspecified listing command, related to "reading from invalid pointer."

1%
Низкий
почти 4 года назад
github логотип
GHSA-p5jc-239c-pvvf

Memory safety bugs present in Firefox 135. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 135.0.1.

CVSS3: 6.5
0%
Низкий
12 месяцев назад
github логотип
GHSA-p5hw-4fxj-g4x6

A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no longer visible. *This bug only affects Firefox Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 131.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-p5g9-gchg-7wgv

js/src/proxy/Proxy.cpp in Mozilla Firefox before 41.0 mishandles certain receiver arguments, which allows remote attackers to bypass intended window access restrictions via a crafted web site.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-p5g7-573c-m74m

Certain canvas operations could have lead to memory corruption. This vulnerability affects Firefox < 139.0.4.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-p5fj-7pgr-xv7v

js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1 allows remote attackers to execute arbitrary code via certain use of the escape function that triggers access to uninitialized memory locations, as originally demonstrated by a document containing P and FONT elements.

83%
Высокий
почти 4 года назад
github логотип
GHSA-p5f8-m753-hvgf

Because Firefox did not implement the <code>unsafe-hashes</code> CSP directive, an attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able to inject executable script. This would be severely constrained by the specified Content Security Policy of the document. This vulnerability affects Firefox < 108.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-p549-c3cg-f4qm

By first using the AI chatbot in one tab and later activating it in another tab, the document title of the previous tab would leak into the chat prompt. This vulnerability affects Firefox < 137.

CVSS3: 5.3
0%
Низкий
10 месяцев назад
github логотип
GHSA-p52p-vjgp-j832

On Linux systems, if the content process is compromised, the sandbox broker will allow files to be truncated even though the sandbox explicitly only has read access to the local file system and no write permissions. Note: This attack only affects the Linux operating system. Other operating systems are not affected. This vulnerability affects Firefox < 55.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-p4qw-x342-xjwx

Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.5 allow remote attackers to execute arbitrary code via a crafted XPCNativeWrapper.

12%
Средний
почти 4 года назад
github логотип
GHSA-p397-mrp5-f5r7

Mozilla developers and community members Calixte Denizet, Gabriele Svelto, Andrew McCreight, and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 110. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 111.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-p364-qwq2-fh4v

Firefox 1.0.6 allows attackers to cause a denial of service (crash) via a Proxy Auto-Config (PAC) script that uses an eval statement. NOTE: it is not clear whether an untrusted party has any role in triggering this issue, so it might not be a vulnerability.

1%
Низкий
почти 4 года назад
github логотип
GHSA-p2g2-wp3h-q672

Spoofing issue in Firefox. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and Firefox ESR < 115.30.

CVSS3: 3.4
0%
Низкий
3 месяца назад
github логотип
GHSA-p2f5-76jq-f5vv

Mozilla developers reported memory safety bugs present in Firefox 88. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 89.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-p26w-gphp-32x2

Content Security Policy combined with HTTP to HTTPS redirection can be used by malicious server to verify whether a known site is within a user's browser history. This vulnerability affects Firefox < 50.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mxw3-h8f2-qrw5

The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-mxfw-955c-c6f5

Firefox 1.0 does not invoke the Javascript Security Manager when a user drags a javascript: or data: URL to a tab, which allows remote attackers to bypass the security model, aka "firetabbing."

3%
Низкий
почти 4 года назад

Уязвимостей на страницу