Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-m7fr-3m5q-g72f

больше 3 лет назад

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.

EPSS: Низкий
github логотип

GHSA-m793-xp46-r76w

11 месяцев назад

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-m688-42p9-r3mv

почти 4 года назад

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.

EPSS: Низкий
github логотип

GHSA-m543-phjx-rgwv

больше 3 лет назад

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-m4xx-wmfj-35cv

больше 3 лет назад

Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.

EPSS: Низкий
github логотип

GHSA-m4x9-6p9j-3hx6

больше 3 лет назад

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-m3v7-47jg-qghf

больше 3 лет назад

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-m3mc-w2qf-4wc3

почти 4 года назад

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."

EPSS: Низкий
github логотип

GHSA-m3g3-73hc-9hqr

больше 3 лет назад

Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.

EPSS: Низкий
github логотип

GHSA-m3ch-2f5c-5pcw

больше 3 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.

EPSS: Низкий
github логотип

GHSA-m2rp-964h-h237

11 месяцев назад

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-m2q8-9rr2-r2ww

больше 3 лет назад

A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, making the resulting location less visibly a spoofed site and showing an incorrect domain in appended notifications. This vulnerability affects Firefox < 53.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-m22j-h75j-625m

почти 4 года назад

Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-jxv6-m6pm-cqh2

около 2 лет назад

Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-jxv2-pgjw-vg3v

около 1 года назад

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-jxmw-fv2p-4289

больше 2 лет назад

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-jx5p-r5h3-74m9

больше 3 лет назад

Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-jx2q-hvww-224r

около 3 лет назад

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-jw9g-hr3v-p6jp

больше 3 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 64.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-jw7x-8w43-2mrj

больше 3 лет назад

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerability affects Firefox < 51.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-m7fr-3m5q-g72f

Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 do not impose certain ECMAScript 6 requirements on JavaScript object properties, which allows remote attackers to bypass the Same Origin Policy via the reviver parameter to the JSON.parse method.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m793-xp46-r76w

Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed (distinct from CVE-2025-0245). This vulnerability affects Firefox < 136.

CVSS3: 9.1
0%
Низкий
11 месяцев назад
github логотип
GHSA-m688-42p9-r3mv

Mozilla Firefox 2.0.0.4 and earlier allows remote attackers to read files in the local Firefox installation directory via a resource:// URI.

1%
Низкий
почти 4 года назад
github логотип
GHSA-m543-phjx-rgwv

If WebRTC permission is requested from documents with data: or blob: URLs, the permission notifications do not properly display the originating domain. The notification states "Unknown origin" as the requestee, leading to user confusion about which site is asking for this permission. This vulnerability affects Firefox < 66.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-m4xx-wmfj-35cv

Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m4x9-6p9j-3hx6

Further techniques that built on the slipstream research combined with a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 85.

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-m3v7-47jg-qghf

The WebGL implementation in Mozilla Firefox 4.x through 4.0.1 does not properly restrict read operations, which allows remote attackers to obtain sensitive information from GPU memory associated with an arbitrary process, or cause a denial of service (application crash), via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m3mc-w2qf-4wc3

The content layout component in Mozilla Firefox 3.0 and 3.0.1 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted but well-formed web page that contains "a simple set of legitimate HTML tags."

1%
Низкий
почти 4 года назад
github логотип
GHSA-m3g3-73hc-9hqr

Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-m3ch-2f5c-5pcw

Cross-site scripting (XSS) vulnerability in Mozilla Firefox 4.x through 4.0.1 allows remote attackers to inject arbitrary web script or HTML via an SVG element containing an HTML-encoded entity.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-m2rp-964h-h237

Websites redirecting to a non-HTTP scheme URL could allow a website address to be spoofed for a malicious page This vulnerability affects Firefox for iOS < 136.

CVSS3: 4.3
0%
Низкий
11 месяцев назад
github логотип
GHSA-m2q8-9rr2-r2ww

A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, making the resulting location less visibly a spoofed site and showing an incorrect domain in appended notifications. This vulnerability affects Firefox < 53.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-m22j-h75j-625m

Unspecified vulnerability in the JavaScript engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

6%
Низкий
почти 4 года назад
github логотип
GHSA-jxv6-m6pm-cqh2

Multiple NSS NIST curves were susceptible to a side-channel attack known as "Minerva". This attack could potentially allow an attacker to recover the private key. This vulnerability affects Firefox < 121.

CVSS3: 4.3
0%
Низкий
около 2 лет назад
github логотип
GHSA-jxv2-pgjw-vg3v

Accessing a non-secure HTTP site that uses a non-existent port may cause the SSL padlock icon in the location URL bar to, misleadingly, appear secure. This vulnerability affects Firefox for iOS < 133.

CVSS3: 5.4
0%
Низкий
около 1 года назад
github логотип
GHSA-jxmw-fv2p-4289

Memory safety bugs present in Firefox 115, Firefox ESR 115.0, Firefox ESR 102.13, Thunderbird 115.0, and Thunderbird 102.13. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 9.8
1%
Низкий
больше 2 лет назад
github логотип
GHSA-jx5p-r5h3-74m9

Buffer overflow in the mozilla::gfx::FilterSupport::ComputeSourceNeededRegions function in Mozilla Firefox before 49.0 allows remote attackers to execute arbitrary code by leveraging improper interaction between empty filters and CANVAS element rendering.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-jx2q-hvww-224r

When downloading an HTML file, if the title of the page was formatted as a filename with a malicious extension, Firefox may have saved the file with that extension, leading to possible system compromise if the downloaded file was later ran. This vulnerability affects Firefox < 107.

CVSS3: 7.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-jw9g-hr3v-p6jp

Mozilla developers and community members reported memory safety bugs present in Firefox 63. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 64.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-jw7x-8w43-2mrj

The "export" function in the Certificate Viewer can force local filesystem navigation when the "common name" in a certificate contains slashes, allowing certificate content to be saved in unsafe locations with an arbitrary filename. This vulnerability affects Firefox < 51.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу