Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-c6mg-xwvh-76jx

около 2 лет назад

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c6fg-jhfr-pxqg

почти 4 года назад

Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.

EPSS: Низкий
github логотип

GHSA-c5wv-fh3j-8jqv

больше 3 лет назад

Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content. This vulnerability affects Firefox < 77.

EPSS: Низкий
github логотип

GHSA-c5vx-c657-hmcm

больше 3 лет назад

A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to bypass the CSP restrictions on executing injected scripts. This vulnerability affects Firefox < 60.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c5pq-336c-xh85

почти 4 года назад

** DISPUTED ** Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that "I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not."

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-c59w-3gff-7wp9

больше 3 лет назад

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-c55w-hjjc-53ww

около 3 лет назад

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c4xq-jjr6-4q6x

больше 3 лет назад

Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c4g9-q4rc-577f

6 месяцев назад

A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-c3x3-j36w-9jmm

больше 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-c379-hcwr-qvc4

больше 3 лет назад

Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.

EPSS: Низкий
github логотип

GHSA-c35j-9mg9-vrr7

больше 3 лет назад

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.

EPSS: Низкий
github логотип

GHSA-c2mm-7gpv-8xqx

почти 4 года назад

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

EPSS: Низкий
github логотип

GHSA-c2m7-wq23-rhm8

больше 3 лет назад

When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-c244-84j9-388q

больше 3 лет назад

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9xmm-8mw4-qgc6

больше 3 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

EPSS: Низкий
github логотип

GHSA-9xm4-hw5v-jpjg

около 2 лет назад

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-9xjq-84qp-q8wh

больше 3 лет назад

The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, mishandles shader access, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted (1) OpenGL or (2) WebGL content.

EPSS: Низкий
github логотип

GHSA-9xhj-7vhh-97qx

больше 3 лет назад

Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.

EPSS: Низкий
github логотип

GHSA-9x34-3cq7-4hf6

7 месяцев назад

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-c6mg-xwvh-76jx

An attacker could have performed HTML template injection via Reader Mode and exfiltrated user information. This vulnerability affects Firefox for iOS < 120.

CVSS3: 6.1
0%
Низкий
около 2 лет назад
github логотип
GHSA-c6fg-jhfr-pxqg

Directory traversal vulnerability in Mozilla Firefox 2.0.0.4 and earlier on Mac OS X and Unix allows remote attackers to read arbitrary files via ..%2F (dot dot encoded slash) sequences in a resource:// URI.

1%
Низкий
почти 4 года назад
github логотип
GHSA-c5wv-fh3j-8jqv

Mozilla Developer Nicolas Silva found that when using WebRender, Firefox would under certain conditions leak arbitrary GPU memory to the visible screen. The leaked memory content was visible to the user, but not observable from web content. This vulnerability affects Firefox < 77.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-c5vx-c657-hmcm

A mechanism to bypass Content Security Policy (CSP) protections on sites that have a "script-src" policy of "'strict-dynamic'". If a target website contains an HTML injection flaw an attacker could inject a reference to a copy of the "require.js" library that is part of Firefox's Developer Tools, and then use a known technique using that library to bypass the CSP restrictions on executing injected scripts. This vulnerability affects Firefox < 60.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c5pq-336c-xh85

** DISPUTED ** Multiple unspecified vulnerabilities in Mozilla Firefox have unspecified vectors and impact, as claimed during ToorCon 2006. NOTE: the vendor and original researchers have released a follow-up comment disputing this issue, in which one researcher states that "I have no undisclosed Firefox vulnerabilities. The person who was speaking with me made this claim, and I honestly have no idea if he has them or not."

CVSS3: 8.1
0%
Низкий
почти 4 года назад
github логотип
GHSA-c59w-3gff-7wp9

The unicode latin 'kra' character can be used to spoof a standard 'k' character in the addressbar. This allows for domain spoofing attacks as do not display as punycode text, allowing for user confusion. This vulnerability affects Firefox < 68.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c55w-hjjc-53ww

A website that had permission to access the microphone could record audio without the audio notification being shown. This bug does not allow the attacker to bypass the permission prompt - it only affects the notification shown once permission has been granted.<br />*This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 104.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-c4xq-jjr6-4q6x

Some unicode characters are incorrectly treated as whitespace during the parsing of web content instead of triggering parsing errors. This allows malicious code to then be processed, evading cross-site scripting (XSS) filtering. This vulnerability affects Firefox < 68.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c4g9-q4rc-577f

A crafted URL using a blob: URI could have hidden the true origin of the page, resulting in a potential spoofing attack. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 141.

CVSS3: 4.3
0%
Низкий
6 месяцев назад
github логотип
GHSA-c3x3-j36w-9jmm

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 37.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-c379-hcwr-qvc4

Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-c35j-9mg9-vrr7

The Off Main Thread Compositing (OMTC) implementation in Mozilla Firefox before 37.0 attempts to use memset for a memory region of negative length during interaction with the mozilla::layers::BufferTextureClient::AllocateForSurface function, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors that trigger rendering of 2D graphics content.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-c2mm-7gpv-8xqx

Integer overflow in the decompression functionality in the Web Open Fonts Format (WOFF) decoder in Mozilla Firefox 3.6 before 3.6.2 and 3.7 before 3.7 alpha 3 allows remote attackers to execute arbitrary code via a crafted WOFF file that triggers a buffer overflow, as demonstrated by the vd_ff module in VulnDisco 9.0.

10%
Низкий
почти 4 года назад
github логотип
GHSA-c2m7-wq23-rhm8

When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-c244-84j9-388q

WebExtension content scripts can be loaded into about: pages in some circumstances, in violation of the permissions granted to extensions. This could allow an extension to interfere with the loading and usage of these pages and use capabilities that were intended to be restricted from extensions. This vulnerability affects Firefox < 64.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9xmm-8mw4-qgc6

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-9xm4-hw5v-jpjg

In some circumstances, JIT compiled code could have dereferenced a wild pointer value. This could have led to an exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 7.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-9xjq-84qp-q8wh

The ProgramBinary::linkAttributes function in libGLES in ANGLE, as used in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows, mishandles shader access, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted (1) OpenGL or (2) WebGL content.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-9xhj-7vhh-97qx

Mozilla Firefox before 40.0 allows man-in-the-middle attackers to bypass a mixed-content protection mechanism via a feed: URL in a POST request.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9x34-3cq7-4hf6

The executable file warning did not warn users before opening files with the `terminal` extension. *This bug only affects Firefox for macOS. Other versions of Firefox are unaffected.* This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 8.8
0%
Низкий
7 месяцев назад

Уязвимостей на страницу