Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-mhm4-c785-rp95

больше 3 лет назад

The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lacks status checking, which allows attackers to have an unspecified impact via vectors related to a cryptographic key.

EPSS: Низкий
github логотип

GHSA-mh57-wf4x-427m

почти 4 года назад

Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.

EPSS: Низкий
github логотип

GHSA-mgw3-h49g-5mxp

больше 3 лет назад

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-mgfp-hcp6-39f4

около 4 лет назад

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

EPSS: Низкий
github логотип

GHSA-mg37-fr9j-7cpg

больше 3 лет назад

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-mfx4-92v4-cw72

почти 4 года назад

Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding

EPSS: Низкий
github логотип

GHSA-mfvj-29wx-4v2c

почти 4 года назад

The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors.

EPSS: Низкий
github логотип

GHSA-mff6-fp66-7vrp

около 2 лет назад

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mf89-9mq2-mmp2

больше 3 лет назад

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-mcm9-29wj-77v9

больше 3 лет назад

The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-mc5v-8859-pvcf

больше 2 лет назад

By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m9x4-cr95-4r8p

почти 4 года назад

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.

EPSS: Низкий
github логотип

GHSA-m9q5-xj5r-c8v2

почти 4 года назад

The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.

EPSS: Низкий
github логотип

GHSA-m9m4-w6qg-qgcp

больше 3 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 88.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-m98j-9vrj-cgp2

больше 3 лет назад

The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect.

EPSS: Низкий
github логотип

GHSA-m8wf-fqcm-6693

больше 2 лет назад

Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m8mw-7m8x-jh2h

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.

EPSS: Низкий
github логотип

GHSA-m8gp-2hwh-pvjg

почти 4 года назад

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element. NOTE: it was later reported that earlier versions are also affected.

EPSS: Средний
github логотип

GHSA-m7v6-rq9x-fwvj

почти 4 года назад

Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.

EPSS: Низкий
github логотип

GHSA-m7pc-jrgg-qm66

больше 3 лет назад

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-mhm4-c785-rp95

The CryptoKey interface implementation in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lacks status checking, which allows attackers to have an unspecified impact via vectors related to a cryptographic key.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-mh57-wf4x-427m

Mozilla Firefox before 0.10.1 allows remote attackers to delete arbitrary files in the download directory via a crafted data: URI that is not properly handled when the user clicks the Save button.

1%
Низкий
почти 4 года назад
github логотип
GHSA-mgw3-h49g-5mxp

Integer underflow in Brotli, as used in Mozilla Firefox before 45.0, allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow) via crafted data with brotli compression.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-mgfp-hcp6-39f4

A Universal XSS vulnerability was present in Firefox for Android resulting from improper sanitization when processing a URL scanned from a QR code. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 94.

7%
Низкий
около 4 лет назад
github логотип
GHSA-mg37-fr9j-7cpg

The combined, single character, version of the letter 'i' with any of the potential accents in unicode, such as acute or grave, can be spoofed in the addressbar by the dotless version of 'i' followed by the same accent as a second character with most font sets. This allows for domain spoofing attacks because these combined domain names do not display as punycode. This vulnerability affects Firefox < 57.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-mfx4-92v4-cw72

Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding

0%
Низкий
почти 4 года назад
github логотип
GHSA-mfvj-29wx-4v2c

The browser engine in Mozilla Firefox 3.5.x before 3.5.2 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the TraceRecorder::snapshot function in js/src/jstracer.cpp, and unspecified other vectors.

7%
Низкий
почти 4 года назад
github логотип
GHSA-mff6-fp66-7vrp

A use-after-free crash could have occurred on macOS if a Firefox update were being applied on a very busy system. This could have resulted in an exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-mf89-9mq2-mmp2

Mozilla Firefox before 49.0 allows remote attackers to bypass the Same Origin Policy via a crafted fragment identifier in the SRC attribute of an IFRAME element, leading to insufficient restrictions on link-color information after a document is resized.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mcm9-29wj-77v9

The Mozilla Maintenance Service "helper.exe" application creates a temporary directory writable by non-privileged users. When this is combined with creation of a junction (a form of symbolic link), protected files in the target directory of the junction can be deleted by the Mozilla Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-mc5v-8859-pvcf

By displaying a prompt with a long description, the fullscreen notification could have been hidden, resulting in potential user confusion or spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 111.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-m9x4-cr95-4r8p

Mozilla Firefox before 3.0.15, and 3.5.x before 3.5.4, allows remote attackers to read form history by forging mouse and keyboard events that leverage the auto-fill feature to populate form fields, in an attacker-readable form, with history entries.

1%
Низкий
почти 4 года назад
github логотип
GHSA-m9q5-xj5r-c8v2

The function allocation code (js_NewFunction in jsfun.c) in Firefox 1.5 allows attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via user-defined methods that trigger garbage collection in a way that operates on freed objects.

4%
Низкий
почти 4 года назад
github логотип
GHSA-m9m4-w6qg-qgcp

Mozilla developers and community members reported memory safety bugs present in Firefox 87. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 88.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-m98j-9vrj-cgp2

The URL parsing implementation in Mozilla Firefox before 42.0 improperly recognizes escaped characters in hostnames within Location headers, which allows remote attackers to obtain sensitive information via vectors involving a redirect.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m8wf-fqcm-6693

Under certain circumstances, a ServiceWorker's offline cache may have leaked to the file system when using private browsing mode. This vulnerability affects Firefox < 111.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-m8mw-7m8x-jh2h

Mozilla developers reported memory safety bugs present in Firefox 82. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 83.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m8gp-2hwh-pvjg

Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory consumption) via a KEYGEN element in conjunction with (1) a META element specifying automatic page refresh or (2) a JavaScript onLoad event handler for a BODY element. NOTE: it was later reported that earlier versions are also affected.

17%
Средний
почти 4 года назад
github логотип
GHSA-m7v6-rq9x-fwvj

Mozilla Firefox before 1.0 is installed with world-writable permissions on Mac OS X, which allows local users to gain privileges.

0%
Низкий
почти 4 года назад
github логотип
GHSA-m7pc-jrgg-qm66

Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, when a Java plugin is enabled, allow remote attackers to cause a denial of service (incorrect garbage collection and application crash) or possibly execute arbitrary code via a crafted Java applet that deallocates an in-use JavaScript wrapper.

2%
Низкий
больше 3 лет назад

Уязвимостей на страницу