Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-cx32-x9h5-xm6c

больше 3 лет назад

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cwgv-fxx6-cp78

больше 3 лет назад

Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a crafted WebRTC RTP packet.

EPSS: Низкий
github логотип

GHSA-crcr-jcjm-54w8

больше 3 лет назад

During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-crcc-3c88-jfqc

больше 3 лет назад

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

EPSS: Низкий
github логотип

GHSA-cr8r-7g9p-hcx6

больше 1 года назад

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cr3m-h7rp-5333

больше 3 лет назад

Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cqj3-wx7w-jfx6

4 месяца назад

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cqhv-5jmg-p8jh

около 3 лет назад

When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-cq34-8vfv-756h

больше 3 лет назад

A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. This could allow an attacker to spoof which page is actually loaded and in use. Note: this issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 59.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-cq2m-7793-8345

больше 3 лет назад

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

EPSS: Низкий
github логотип

GHSA-cpxq-p6pr-9jf6

около 3 лет назад

By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only affects Firefox for Windows and MacOS. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cpqh-mhhx-jwmj

почти 4 года назад

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.

EPSS: Низкий
github логотип

GHSA-cpfv-mr66-74v6

больше 1 года назад

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cmw5-xxqm-3g4q

почти 4 года назад

Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

EPSS: Низкий
github логотип

GHSA-cmfr-9hrr-hpg4

больше 3 лет назад

When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.

EPSS: Низкий
github логотип

GHSA-cm6f-xjjv-f446

больше 3 лет назад

A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-cm37-53wc-mx6g

почти 2 года назад

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.

CVSS3: 8.4
EPSS: Низкий
github логотип

GHSA-cm2q-67xf-jw8c

больше 3 лет назад

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
EPSS: Низкий
github логотип

GHSA-ch5f-5368-9hw8

больше 3 лет назад

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-cgpr-293c-5r54

больше 3 лет назад

When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-cx32-x9h5-xm6c

By causing a transition on a parent node by removing a CSS rule, an invalid property for a marker could have been applied, resulting in memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 87.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-cwgv-fxx6-cp78

Integer underflow in the RTPReceiverVideo::ParseRtpPacket function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 might allow remote attackers to obtain sensitive information, cause a denial of service, or possibly have unspecified other impact by triggering a crafted WebRTC RTP packet.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-crcr-jcjm-54w8

During URL parsing, a maliciously crafted URL can cause a potentially exploitable crash. This vulnerability affects Firefox < 50.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-crcc-3c88-jfqc

When accepting a malicious intent from other installed apps, Firefox for Android accepted manifests from arbitrary file paths and allowed declaring webapp manifests for other origins. This could be used to gain fullscreen access for UI spoofing and could also lead to cross-origin attacks on targeted websites. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 83.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cr8r-7g9p-hcx6

Long pressing on a download link could potentially allow Javascript commands to be executed within the browser This vulnerability affects Firefox for iOS < 129.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-cr3m-h7rp-5333

Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-cqj3-wx7w-jfx6

When the address bar was hidden due to scrolling on Android, a malicious page could create a fake address bar to fool the user in response to a visibilitychange event This vulnerability affects Firefox < 144.

CVSS3: 6.5
0%
Низкий
4 месяца назад
github логотип
GHSA-cqhv-5jmg-p8jh

When scanning QR codes, Firefox for Android would have allowed navigation to some URLs that do not point to web content.<br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-cq34-8vfv-756h

A spoofing vulnerability can occur when a malicious site with an extremely long domain name is opened in an Android Custom Tab (a browser panel inside another app) and the default browser is Firefox for Android. This could allow an attacker to spoof which page is actually loaded and in use. Note: this issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 59.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cq2m-7793-8345

NetworkUtils.cpp in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 might allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-cpxq-p6pr-9jf6

By generally accepting and passing resource handles across processes, a compromised content process might have confused higher privileged processes to interact with handles that the unprivileged process should not have access to.<br>*This bug only affects Firefox for Windows and MacOS. Other operating systems are unaffected.*. This vulnerability affects Firefox < 96.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-cpqh-mhhx-jwmj

Multiple unspecified vulnerabilities in Mozilla Firefox 3.x before 3.0.2 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to graphics rendering and (1) handling of a long alert messagebox in the cairo_surface_set_device_offset function, (2) integer overflows when handling animated PNG data in the info_callback function in nsPNGDecoder.cpp, and (3) an integer overflow when handling SVG data in the nsSVGFEGaussianBlurElement::SetupPredivide function in nsSVGFilters.cpp.

2%
Низкий
почти 4 года назад
github логотип
GHSA-cpfv-mr66-74v6

Firefox Android allowed immediate interaction with permission prompts. This could be used for tapjacking. This vulnerability affects Firefox < 128.

CVSS3: 8.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-cmw5-xxqm-3g4q

Firefox and Mozilla allow remote attackers to cause a denial of service (application crash from memory consumption), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.

1%
Низкий
почти 4 года назад
github логотип
GHSA-cmfr-9hrr-hpg4

When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authority or session fixation. This was resolved by only allowing certain safe-listed headers. *Note: This issue only affected Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-cm6f-xjjv-f446

A malicious extension could have called <code>browser.identity.launchWebAuthFlow</code>, controlling the redirect_uri, and through the Promise returned, obtain the Auth code and gain access to the user's account at the service provider. This vulnerability affects Firefox < 75.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-cm37-53wc-mx6g

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. This vulnerability affects Firefox < 124.0.1 and Firefox ESR < 115.9.1.

CVSS3: 8.4
1%
Низкий
почти 2 года назад
github логотип
GHSA-cm2q-67xf-jw8c

During ECDSA signature generation, padding applied in the nonce designed to ensure constant-time scalar multiplication was removed, resulting in variable-time execution dependent on secret data. This vulnerability affects Firefox < 80 and Firefox for Android < 80.

CVSS3: 4.7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-ch5f-5368-9hw8

If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example.com"), the resulting modal prompt will hang in a non-responsive state or crash, causing a denial of service. This vulnerability affects Firefox < 55.

CVSS3: 7.5
7%
Низкий
больше 3 лет назад
github логотип
GHSA-cgpr-293c-5r54

When JavaScript is used to create and manipulate an audio buffer, a potentially exploitable crash may occur because of a compartment mismatch in some situations. This vulnerability affects Firefox < 65.

CVSS3: 8.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу