Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-9g93-p34g-x5f6

больше 2 лет назад

A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-9fw5-r669-cvr3

больше 2 лет назад

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9fqh-jpcp-95fv

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 90.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9fmf-gjw2-hq6p

больше 3 лет назад

A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9fhg-wr6f-g4x9

больше 3 лет назад

Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-9f9w-vwq3-c9fh

больше 3 лет назад

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-9f8v-397v-w8c6

около 2 лет назад

Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-9f34-96p5-45qg

больше 3 лет назад

A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. This allows an attacker to spoof which page is actually loaded and in use. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 56.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9cm2-qg89-qv3m

больше 3 лет назад

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

EPSS: Низкий
github логотип

GHSA-99j5-vg32-77h3

больше 3 лет назад

Mozilla Firefox before 20.0 on Android uses world-writable and world-readable permissions for the app_tmp installation directory in the local filesystem, which allows attackers to modify add-ons before installation via an application that leverages the time window during which app_tmp is used.

EPSS: Низкий
github логотип

GHSA-99c3-fh27-qg5q

больше 3 лет назад

The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."

EPSS: Низкий
github логотип

GHSA-994h-6rhw-f376

больше 3 лет назад

Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the title of a website visited during private browsing mode being stored on disk. This vulnerability affects Firefox < 89.

EPSS: Низкий
github логотип

GHSA-9897-h6f7-gvh5

больше 3 лет назад

If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests. This vulnerability affects Firefox < 57.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-985w-c5f5-7374

больше 3 лет назад

The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-97x9-7h6v-3jx9

больше 1 года назад

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-97gg-j6v9-fvp7

больше 3 лет назад

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50. This vulnerability affects Firefox < 50.0.1.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-976p-wp36-p43w

больше 3 лет назад

A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited because the memory is freed and reused in a brief window of time during the freeing of the same callstack. This vulnerability affects Firefox < 60.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-96vc-phqg-v5rx

6 месяцев назад

Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-96fh-38m4-95mm

почти 4 года назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-969j-v3p3-p4vv

больше 2 лет назад

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-9g93-p34g-x5f6

A website could have obscured the fullscreen notification by using an option element by introducing lag via an expensive computational function. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 115.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-9fw5-r669-cvr3

In some circumstances, a stale value could have been used for a global variable in WASM JIT analysis. This resulted in incorrect compilation and a potentially exploitable crash in the content process. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-9fqh-jpcp-95fv

Mozilla developers reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 90.

CVSS3: 8.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9fmf-gjw2-hq6p

A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9fhg-wr6f-g4x9

Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1.

CVSS3: 6.1
1%
Низкий
больше 3 лет назад
github логотип
GHSA-9f9w-vwq3-c9fh

The Firefox Health Reports (aka FHR or about:healthreport) feature in Mozilla Firefox before 46.0 does not properly restrict the origin of events, which makes it easier for remote attackers to modify sharing preferences by leveraging access to the remote-report IFRAME element.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9f8v-397v-w8c6

Memory safety bugs present in Firefox 120. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 121.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-9f34-96p5-45qg

A spoofing vulnerability can occur when a page switches to fullscreen mode without user notification, allowing a fake address bar to be displayed. This allows an attacker to spoof which page is actually loaded and in use. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 56.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-9cm2-qg89-qv3m

The WebRTC subsystem in Mozilla Firefox before 36.0 recognizes turns: and stuns: URIs but accesses the TURN or STUN server without using TLS, which makes it easier for man-in-the-middle attackers to discover credentials by spoofing a server and completing a brute-force attack within a short time window.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-99j5-vg32-77h3

Mozilla Firefox before 20.0 on Android uses world-writable and world-readable permissions for the app_tmp installation directory in the local filesystem, which allows attackers to modify add-ons before installation via an application that leverages the time window during which app_tmp is used.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-99c3-fh27-qg5q

The nsTSubstring::ReplacePrep function in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, related to an "overflow."

3%
Низкий
больше 3 лет назад
github логотип
GHSA-994h-6rhw-f376

Firefox used to cache the last filename used for printing a file. When generating a filename for printing, Firefox usually suggests the web page title. The caching and suggestion techniques combined may have lead to the title of a website visited during private browsing mode being stored on disk. This vulnerability affects Firefox < 89.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-9897-h6f7-gvh5

If a document's Referrer Policy attribute is set to "no-referrer" sometimes two network requests are made for "<link>" elements instead of one. One of these requests includes the referrer instead of respecting the set policy to not include a referrer on requests. This vulnerability affects Firefox < 57.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-985w-c5f5-7374

The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.

CVSS3: 9.8
4%
Низкий
больше 3 лет назад
github логотип
GHSA-97x9-7h6v-3jx9

An attacker could write data to the user's clipboard, bypassing the user prompt, during a certain sequence of navigational events. This vulnerability affects Firefox < 129.

CVSS3: 7.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-97gg-j6v9-fvp7

Redirection from an HTTP connection to a "data:" URL assigns the referring site's origin to the "data:" URL in some circumstances. This can result in same-origin violations against a domain if it loads resources from malicious sites. Cross-origin setting of cookies has been demonstrated without the ability to read them. Note: This issue only affects Firefox 49 and 50. This vulnerability affects Firefox < 50.0.1.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-976p-wp36-p43w

A use-after-free vulnerability can occur during WebGL operations. While this results in a potentially exploitable crash, the vulnerability is limited because the memory is freed and reused in a brief window of time during the freeing of the same callstack. This vulnerability affects Firefox < 60.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-96vc-phqg-v5rx

Spoofing issue in the Address Bar component of Firefox Focus for Android. This vulnerability affects Firefox < 142.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
github логотип
GHSA-96fh-38m4-95mm

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14, and 3.5.x before 3.5.2, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

3%
Низкий
почти 4 года назад
github логотип
GHSA-969j-v3p3-p4vv

An out-of-bounds read could have led to an exploitable crash when parsing HTML with DOMParser in low memory situations. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу