Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17 208

Количество 17 208

github логотип

GHSA-xc8j-mr73-m6wv

больше 2 лет назад

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x9h6-qwxm-528g

больше 1 года назад

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
EPSS: Низкий
github логотип

GHSA-x945-jm33-f3qv

больше 2 лет назад

Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x8v2-79v9-cjv2

около 4 лет назад

Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering attempted use of a data channel that has been closed by a WebRTC function.

EPSS: Низкий
github логотип

GHSA-x8mw-7jxq-c26v

около 4 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 67.

EPSS: Низкий
github логотип

GHSA-x8jx-j549-3mc7

около 4 лет назад

A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-x85x-whmj-686x

около 4 лет назад

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-x7x8-qh7j-2q6h

больше 3 лет назад

When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-x7hr-j7rg-h68w

12 месяцев назад

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-x73f-6qwm-hh3x

больше 2 лет назад

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x63v-c8hj-q3pw

около 4 лет назад

The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.

EPSS: Низкий
github логотип

GHSA-x5xq-hf4g-4cgq

больше 4 лет назад

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affects Firefox < 94.

EPSS: Низкий
github логотип

GHSA-x5ph-343m-g2xh

около 4 лет назад

CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.

EPSS: Низкий
github логотип

GHSA-x5jm-2j58-gxgp

около 4 лет назад

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

EPSS: Низкий
github логотип

GHSA-x4vx-jp8h-mrcx

около 2 лет назад

Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have lead to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-x4p9-6wvp-vc8f

около 4 лет назад

Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x4p5-q86p-74vp

около 4 лет назад

The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context. This vulnerability affects Firefox < 60.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-x4mq-76g8-78f6

около 4 лет назад

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-x428-6vv2-wx8p

около 3 лет назад

A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.

CVSS3: 10
EPSS: Низкий
github логотип

GHSA-x3xw-gpqw-j8j2

около 4 лет назад

Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xc8j-mr73-m6wv

In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-x9h6-qwxm-528g

Android apps can load web pages using the Custom Tabs feature. This feature supports a transition animation that could have been used to trick a user into granting sensitive permissions by hiding what the user was actually clicking. This vulnerability affects Firefox < 136.

CVSS3: 3.9
0%
Низкий
больше 1 года назад
github логотип
GHSA-x945-jm33-f3qv

Dragging Javascript URLs to the address bar could cause them to be loaded, bypassing restrictions and security protections This vulnerability affects Firefox for iOS < 124.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-x8v2-79v9-cjv2

Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering attempted use of a data channel that has been closed by a WebRTC function.

4%
Низкий
около 4 лет назад
github логотип
GHSA-x8mw-7jxq-c26v

Mozilla developers and community members reported memory safety bugs present in Firefox 66. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 67.

1%
Низкий
около 4 лет назад
github логотип
GHSA-x8jx-j549-3mc7

A use-after-free vulnerability can occur in the compositor during certain graphics operations when a raw pointer is used instead of a reference counted one. This results in a potentially exploitable crash. This vulnerability affects Firefox ESR < 52.7.3 and Firefox < 59.0.2.

CVSS3: 9.8
3%
Низкий
около 4 лет назад
github логотип
GHSA-x85x-whmj-686x

Unsanitized output in the browser UI leaves HTML tags in place and can result in arbitrary code execution in Firefox before version 58.0.1.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-x7x8-qh7j-2q6h

When clicking on a tel: link, USSD codes, specified after a <code>\*</code> character, would be included in the phone number. On certain phones, or on certain carriers, if the number was dialed this could perform actions on a user's account, similar to a cross-site request forgery attack.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 97.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-x7hr-j7rg-h68w

Sandboxed iframes on webpages could potentially allow downloads to the device, bypassing the expected sandbox restrictions declared on the parent page This vulnerability affects Firefox for iOS < 141.

CVSS3: 9.8
0%
Низкий
12 месяцев назад
github логотип
GHSA-x73f-6qwm-hh3x

A compromised content process could have updated the document URI. This could have allowed an attacker to set an arbitrary URI in the address bar or history. This vulnerability affects Firefox < 122.

CVSS3: 4.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-x63v-c8hj-q3pw

The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.

3%
Низкий
около 4 лет назад
github логотип
GHSA-x5xq-hf4g-4cgq

The 'Copy Image Link' context menu action would copy the final image URL after redirects. By embedding an image that triggered authentication flows - in conjunction with a Content Security Policy that stopped a redirection chain in the middle - the final image URL could be one that contained an authentication token used to takeover a user account. If a website tricked a user into copy and pasting the image link back to the page, the page would be able to steal the authentication tokens. This was fixed by making the action return the original URL, before any redirects. This vulnerability affects Firefox < 94.

1%
Низкий
больше 4 лет назад
github логотип
GHSA-x5ph-343m-g2xh

CRLF injection vulnerability in Mozilla Firefox before 2.0.0.12 allows remote user-assisted web sites to corrupt the user's password store via newlines that are not properly handled when the user saves a password.

1%
Низкий
около 4 лет назад
github логотип
GHSA-x5jm-2j58-gxgp

Mozilla Firefox 3.0.7 on Windows 7 allows remote attackers to execute arbitrary code via unknown vectors related to the _moveToEdgeShift XUL tree method, which triggers garbage collection on objects that are still in use, as demonstrated by Nils during a PWN2OWN competition at CanSecWest 2009.

6%
Низкий
около 4 лет назад
github логотип
GHSA-x4vx-jp8h-mrcx

Different techniques existed to obscure the fullscreen notification in Firefox for Android. These could have lead to potential user confusion and spoofing attacks. *This bug only affects Firefox for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 126.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-x4p9-6wvp-vc8f

Mixed-content checks were unable to analyze opaque origins which led to some mixed content being loaded. This vulnerability affects Firefox < 92.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-x4p5-q86p-74vp

The JSON Viewer displays clickable hyperlinks for strings that are parseable as URLs, including "javascript:" links. If a JSON file contains malicious JavaScript script embedded as "javascript:" links, users may be tricked into clicking and running this code in the context of the JSON Viewer. This can allow for the theft of cookies and authorization tokens which are accessible to that context. This vulnerability affects Firefox < 60.

CVSS3: 6.1
1%
Низкий
около 4 лет назад
github логотип
GHSA-x4mq-76g8-78f6

Mozilla Firefox before 46.0 on Android does not properly restrict JavaScript access to orientation and motion data, which allows remote attackers to obtain sensitive information about a device's physical environment, and possibly discover PIN values, via a crafted web site, a similar issue to CVE-2016-1780.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-x428-6vv2-wx8p

A compromised child process could have injected XBL Bindings into privileged CSS rules, resulting in arbitrary code execution and a sandbox escape. This vulnerability affects Firefox < 70.

CVSS3: 10
1%
Низкий
около 3 лет назад
github логотип
GHSA-x3xw-gpqw-j8j2

Firefox before 1.0.1 allows remote attackers to spoof the (1) security and (2) download modal dialog boxes, which could be used to trick users into executing script or downloading and executing a file, aka "Firespoofing."

2%
Низкий
около 4 лет назад

Уязвимостей на страницу