Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-f8rp-8hgw-hrhp

больше 3 лет назад

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.

EPSS: Низкий
github логотип

GHSA-f7vm-6g4j-64q8

около 3 лет назад

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34482. This vulnerability affects Firefox < 102.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-f7gf-49mv-q3m5

почти 4 года назад

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.

EPSS: Низкий
github логотип

GHSA-f7fv-7rmr-mpcf

почти 4 года назад

Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663.

EPSS: Низкий
github логотип

GHSA-f7c8-7wc6-wrv3

больше 3 лет назад

The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-f78g-xm2r-gm6j

больше 1 года назад

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-f775-fgwg-5qvw

больше 3 лет назад

Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 61.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-f748-8jpw-r245

больше 3 лет назад

A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website to query user history. Note: This issue only affects Firefox 57. Earlier releases are not affected. This vulnerability affects Firefox < 57.0.1.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-f5q8-q9fw-rc2j

больше 2 лет назад

Mozilla developers Timothy Nikkel, Gabriele Svelto, Jeff Muizelaar and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-f5p6-qx62-vpqv

больше 3 лет назад

Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-f5cj-6cmj-4fh4

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81.

EPSS: Низкий
github логотип

GHSA-f56r-gj93-xc2f

больше 3 лет назад

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-f423-gp4j-x9mg

больше 3 лет назад

A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potentially exploitable crash. This vulnerability affects Firefox < 59.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-f3g9-x4jw-849g

больше 3 лет назад

An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

EPSS: Низкий
github логотип

GHSA-f235-r39g-2m8r

почти 4 года назад

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

EPSS: Низкий
github логотип

GHSA-cxh5-m5cc-6w2r

больше 3 лет назад

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cxc7-m7pw-q6p7

больше 3 лет назад

Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects Firefox < 76.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cx8j-rw45-8cwm

больше 3 лет назад

A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cx7x-p2rh-c2m2

больше 3 лет назад

A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. This vulnerability affects Firefox < 90.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cx3x-8cg7-v23q

больше 3 лет назад

Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-f8rp-8hgw-hrhp

maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f7vm-6g4j-64q8

An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension, and by extension potentially tricked the user into executing malicious code. While very similar, this is a separate issue from CVE-2022-34482. This vulnerability affects Firefox < 102.

CVSS3: 8.8
1%
Низкий
около 3 лет назад
github логотип
GHSA-f7gf-49mv-q3m5

Cross-domain vulnerability in js/src/jsobj.cpp in Mozilla Firefox 3.x before 3.0.6 allows remote attackers to bypass the Same Origin Policy, and access the properties of an arbitrary window and conduct cross-site scripting (XSS) attacks, via vectors involving a chrome XBL method and the window.eval function.

1%
Низкий
почти 4 года назад
github логотип
GHSA-f7fv-7rmr-mpcf

Multiple unspecified vulnerabilities in libvorbis, as used in Mozilla Firefox 3.5.x before 3.5.4, allow remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors. NOTE: this might overlap CVE-2009-2663.

5%
Низкий
почти 4 года назад
github логотип
GHSA-f7c8-7wc6-wrv3

The maintenance service in Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 on Windows does not prevent MAR extracted-file modification during updater execution, which might allow local users to gain privileges via a Trojan horse file.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-f78g-xm2r-gm6j

In certain scenarios a malicious website could attempt to display a fake location URL bar which could mislead users as to the actual website address This vulnerability affects Firefox for iOS < 127.

CVSS3: 4.3
0%
Низкий
больше 1 года назад
github логотип
GHSA-f775-fgwg-5qvw

Memory safety bugs present in Firefox 60. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 61.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-f748-8jpw-r245

A combination of an external SVG image referenced on a page and the coloring of anchor links stored within this image can be used to determine which pages a user has in their history. This can allow a malicious website to query user history. Note: This issue only affects Firefox 57. Earlier releases are not affected. This vulnerability affects Firefox < 57.0.1.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-f5q8-q9fw-rc2j

Mozilla developers Timothy Nikkel, Gabriele Svelto, Jeff Muizelaar and the Mozilla Fuzzing Team reported memory safety bugs present in Firefox 109. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 110.

CVSS3: 8.8
0%
Низкий
больше 2 лет назад
github логотип
GHSA-f5p6-qx62-vpqv

Mozilla Firefox before 44.0 allows user-assisted remote attackers to spoof a trailing substring in the address bar by leveraging a user's paste of a (1) wyciwyg: URI or (2) resource: URI.

CVSS3: 7.4
1%
Низкий
больше 3 лет назад
github логотип
GHSA-f5cj-6cmj-4fh4

Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 81.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f56r-gj93-xc2f

The nsDisplayList::HitTest function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 mishandles rendering display transformation, which allows remote attackers to execute arbitrary code via a crafted web site that leverages "type confusion."

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-f423-gp4j-x9mg

A use-after-free vulnerability can occur when manipulating elements, events, and selection ranges during editor operations. This results in a potentially exploitable crash. This vulnerability affects Firefox < 59.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-f3g9-x4jw-849g

An XSS bug in internal error pages could have led to various spoofing attacks, including other error pages and the address bar. Note: This issue only affected Firefox for Android. Other operating systems are unaffected. This vulnerability affects Firefox < 85.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-f235-r39g-2m8r

Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."

2%
Низкий
почти 4 года назад
github логотип
GHSA-cxh5-m5cc-6w2r

Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-cxc7-m7pw-q6p7

Documents formed using data: URLs in an OBJECT element failed to inherit the CSP of the creating context. This allowed the execution of scripts that should have been blocked, albeit with a unique opaque origin. This vulnerability affects Firefox < 76.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cx8j-rw45-8cwm

A previously installed malicious Android application with same signature-level permissions as Firefox can intercept AuthTokens meant for Firefox only. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cx7x-p2rh-c2m2

A use-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. This vulnerability affects Firefox < 90.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-cx3x-8cg7-v23q

Race condition in libvpx in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via unknown vectors.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу