Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-g384-9299-vj9w

почти 4 года назад

Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.

EPSS: Низкий
github логотип

GHSA-g2r3-r98c-7g53

больше 3 лет назад

Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

EPSS: Низкий
github логотип

GHSA-g22c-72wp-3974

больше 3 лет назад

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-fxqm-4c8h-5v9p

больше 3 лет назад

Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.

EPSS: Низкий
github логотип

GHSA-fx9q-pwrj-mfh7

больше 3 лет назад

When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected. This vulnerability affects Firefox < 50.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-fx26-f545-4qg3

больше 3 лет назад

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.

EPSS: Низкий
github логотип

GHSA-fwcv-j34v-fh3m

больше 3 лет назад

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.

EPSS: Средний
github логотип

GHSA-fw74-c57g-483q

больше 3 лет назад

Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-fw5c-gh38-g4gg

больше 3 лет назад

The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-fvvm-pp96-j72m

почти 2 года назад

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-fvqv-c5hj-jcrp

7 месяцев назад

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `&lt;embed&gt;` or `&lt;object&gt;` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-fv35-f685-jqpw

больше 3 лет назад

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.

EPSS: Низкий
github логотип

GHSA-frv7-g69x-8pp3

больше 3 лет назад

The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site.

EPSS: Низкий
github логотип

GHSA-frqr-7x7p-q8jj

больше 3 лет назад

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-frpx-rg9c-cvmm

почти 4 года назад

Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.

EPSS: Низкий
github логотип

GHSA-frpv-8jj9-m3cv

больше 1 года назад

By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-frpp-99pq-vjpv

больше 3 лет назад

Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-frj5-x46r-24w8

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.

EPSS: Низкий
github логотип

GHSA-fqhq-pc8v-8xch

больше 3 лет назад

A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-fq4p-86v9-5w3x

больше 3 лет назад

WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-g384-9299-vj9w

Multiple "missing security checks" in Firefox before 1.0.3 allow remote attackers to inject arbitrary Javascript into privileged pages using the _search target of the Firefox sidebar.

1%
Низкий
почти 4 года назад
github логотип
GHSA-g2r3-r98c-7g53

Mozilla Firefox before 38.0 on Android does not properly restrict writing URL data to the Android logging system, which allows attackers to obtain sensitive information via a crafted application that has a required permission for reading a log, as demonstrated by the READ_LOGS permission for the mixed-content violation log on Android 4.0 and earlier.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-g22c-72wp-3974

A non-existent chrome.manifest file will attempt to be loaded during startup from the primary installation directory. If a malicious user with local access puts chrome.manifest and other referenced files in this directory, they will be loaded and activated during startup. This could result in malicious software being added without consent or modification of referenced installed files. This vulnerability affects Firefox < 52.

CVSS3: 5.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fxqm-4c8h-5v9p

Mozilla Firefox before 31.1 on Android does not properly restrict copying of local files onto the SD card during processing of file: URLs, which allows attackers to obtain sensitive information from the Firefox profile directory via a crafted application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-1515.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-fx9q-pwrj-mfh7

When a new Firefox profile is created on 64-bit Windows installations, the sandbox for 64-bit NPAPI plugins is not enabled by default. Note: This issue only affects 64-bit Windows. 32-bit Windows and other operating systems are unaffected. This vulnerability affects Firefox < 50.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fx26-f545-4qg3

The Search feature in Mozilla Firefox before 42.0 on Android through 4.4 supports search-engine URL registration through an intent and can access this URL in a privileged context in conjunction with the crash reporter, which allows attackers to read log files and visit file: URLs of HTML documents via a crafted application.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fwcv-j34v-fh3m

layout/generic/nsObjectFrame.cpp in Mozilla Firefox 3.6.7 does not properly free memory in the parameter array of a plugin instance, which allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted HTML document, related to the DATA and SRC attributes of an OBJECT element. NOTE: this vulnerability exists because of an incorrect fix for CVE-2010-1214.

10%
Средний
больше 3 лет назад
github логотип
GHSA-fw74-c57g-483q

Use-after-free vulnerability in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 allows remote attackers to execute arbitrary code via WebGL content that triggers texture access after destruction of the texture's recycle pool.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-fw5c-gh38-g4gg

The PropertyProvider::GetSpacingInternal function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via text runs in conjunction with a "display: contents" Cascading Style Sheets (CSS) property.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fvvm-pp96-j72m

The MarkStack assignment operator, part of the JavaScript engine, could access uninitialized memory if it were used in a self-assignment. This vulnerability affects Firefox < 125.

CVSS3: 5.3
0%
Низкий
почти 2 года назад
github логотип
GHSA-fvqv-c5hj-jcrp

When a file download is specified via the `Content-Disposition` header, that directive would be ignored if the file was included via a `&lt;embed&gt;` or `&lt;object&gt;` tag, potentially making a website vulnerable to a cross-site scripting attack. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.1
0%
Низкий
7 месяцев назад
github логотип
GHSA-fv35-f685-jqpw

Multiple integer overflows in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allow remote attackers to execute arbitrary code via a crafted saio chunk in MPEG-4 video data.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-frv7-g69x-8pp3

The Profiler implementation in Mozilla Firefox before 22.0 parses untrusted data during UI rendering, which allows user-assisted remote attackers to execute arbitrary JavaScript code via a crafted web site.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-frqr-7x7p-q8jj

The default webcal: protocol handler will load a web site vulnerable to cross-site scripting (XSS) attacks. This default was left in place as a legacy feature and has now been removed. *Note: this issue only affects users with an account on the vulnerable service. Other users are unaffected.*. This vulnerability affects Firefox < 67.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-frpx-rg9c-cvmm

Mozilla Firefox 2.0.0.14 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly execute arbitrary code by triggering an error condition during certain Iframe operations between a JSframe write and a JSframe close, as demonstrated by an error in loading an empty Java applet defined by a 'src="javascript:"' sequence.

5%
Низкий
почти 4 года назад
github логотип
GHSA-frpv-8jj9-m3cv

By manipulating the fullscreen feature while opening a data-list, an attacker could have overlaid a text box over the address bar. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 127.

CVSS3: 6.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-frpp-99pq-vjpv

Mozilla Firefox before 47.0 allows remote attackers to bypass the Same Origin Policy and modify the location.host property via an invalid data: URL.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-frj5-x46r-24w8

Mozilla developers reported memory safety bugs present in Firefox 83. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-fqhq-pc8v-8xch

A latent vulnerability exists in the Prio library where data may be read from uninitialized memory for some functions, leading to potential memory corruption. This vulnerability affects Firefox < 66.

CVSS3: 9.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-fq4p-86v9-5w3x

WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу