Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-95j5-rfpg-w4rp

больше 3 лет назад

The (1) AddWeightedPathSegLists and (2) SVGPathSegListSMILType::Interpolate functions in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lack status checking, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted SVG document.

EPSS: Низкий
github логотип

GHSA-9564-97j4-99c4

больше 3 лет назад

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-953p-grm5-8vpv

больше 3 лет назад

Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-94xm-6p97-mrv4

больше 3 лет назад

Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-94c3-g97c-h69h

больше 3 лет назад

Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing a malformed video and leveraging a Gecko Media Plugin (GMP) sandbox bypass.

CVSS3: 6.3
EPSS: Низкий
github логотип

GHSA-947q-v9mc-gqp3

больше 3 лет назад

A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-9467-r3c9-7387

больше 3 лет назад

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-942w-8v4f-46qw

больше 3 лет назад

The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-93j6-6353-95h4

больше 3 лет назад

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.

EPSS: Низкий
github логотип

GHSA-93gv-w5cx-phvx

около 2 лет назад

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-93fp-mg63-wc9r

больше 3 лет назад

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-92vw-cm5r-xg2f

больше 3 лет назад

A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-92jp-cp3m-jm4c

больше 3 лет назад

Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.

CVSS3: 7
EPSS: Низкий
github логотип

GHSA-9245-f8m8-7x9w

больше 3 лет назад

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.

EPSS: Низкий
github логотип

GHSA-8x5c-gxjr-32f8

больше 3 лет назад

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element.

EPSS: Низкий
github логотип

GHSA-8w77-hpx9-8fm3

около 1 года назад

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8w37-959h-v45j

почти 4 года назад

The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.

EPSS: Низкий
github логотип

GHSA-8vhf-hgr9-gmr5

больше 3 лет назад

Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data that is mishandled during clipping-region calculations.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-8vfr-cjhj-gw7x

почти 4 года назад

Mozilla Firefox allows remote attackers to cause a denial of service (crash) via crafted image, as demonstrated by the zzuf lol-firefox.gif test case.

EPSS: Низкий
github логотип

GHSA-8vcf-c8hj-wp5r

почти 4 года назад

Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-95j5-rfpg-w4rp

The (1) AddWeightedPathSegLists and (2) SVGPathSegListSMILType::Interpolate functions in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 lack status checking, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted SVG document.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-9564-97j4-99c4

If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-953p-grm5-8vpv

Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-94xm-6p97-mrv4

Use-after-free vulnerability in Web Animations when interacting with cycle collection found through fuzzing. This vulnerability affects Firefox < 51.

CVSS3: 7.5
2%
Низкий
больше 3 лет назад
github логотип
GHSA-94c3-g97c-h69h

Heap-based buffer overflow in the ClearKey Content Decryption Module (CDM) in the Encrypted Media Extensions (EME) API in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 might allow remote attackers to execute arbitrary code by providing a malformed video and leveraging a Gecko Media Plugin (GMP) sandbox bypass.

CVSS3: 6.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-947q-v9mc-gqp3

A memory corruption vulnerability in Skia that can occur when using transforms to make gradients, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 51.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-9467-r3c9-7387

Limitations on the URIs allowed to WebExtensions by the browser.windows.create API can be bypassed when a pipe in the URL field is used within the extension to load multiple pages as a single argument. This could allow a malicious WebExtension to open privileged about: or file: locations. This vulnerability affects Firefox < 64.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-942w-8v4f-46qw

The mozilla::net::IsValidReferrerPolicy function in Mozilla Firefox before 49.0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a Content Security Policy (CSP) referrer directive with zero values.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-93j6-6353-95h4

When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code execution. Within Firefox as released by Mozilla, this issue is only exploitable with the Mozilla-controlled signing key. This vulnerability affects Firefox < 80.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-93gv-w5cx-phvx

The WebAudio `OscillatorNode` object was susceptible to a stack buffer overflow. This could have led to a potentially exploitable crash. This vulnerability affects Firefox < 122.

CVSS3: 8.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-93fp-mg63-wc9r

Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-92vw-cm5r-xg2f

A use-after-free in nsINode::ReplaceOrInsertBefore during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.

CVSS3: 7.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-92jp-cp3m-jm4c

Canvas allows the use of the "feDisplacementMap" filter on images loaded cross-origin. The rendering by the filter is variable depending on the input pixel, allowing for timing attacks when the images are loaded from third party locations. This vulnerability affects Firefox < 50.

CVSS3: 7
0%
Низкий
больше 3 лет назад
github логотип
GHSA-9245-f8m8-7x9w

The Reader mode feature in Mozilla Firefox before 37.0.1 on Android, and Desktop Firefox pre-release, does not properly handle privileged URLs, which makes it easier for remote attackers to execute arbitrary JavaScript code with chrome privileges by leveraging the ability to bypass the Same Origin Policy.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-8x5c-gxjr-32f8

Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow user-assisted remote attackers to bypass intended access restrictions and discover a redirect's target URL via crafted JavaScript code that executes after a drag-and-drop action of an image into a TEXTBOX element.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8w77-hpx9-8fm3

A malicious website could have included an iframe with an malformed URI resulting in a non-exploitable browser crash. This vulnerability affects Firefox < 126.

CVSS3: 6.5
0%
Низкий
около 1 года назад
github логотип
GHSA-8w37-959h-v45j

The nsGIFDecoder2::GifWrite function in decoders/gif/nsGIFDecoder2.cpp in libpr0n in Mozilla Firefox before 3.5.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via an animated GIF file with a large image size, a different vulnerability than CVE-2009-3373.

1%
Низкий
почти 4 года назад
github логотип
GHSA-8vhf-hgr9-gmr5

Stack-based buffer underflow in the mozilla::gfx::BasePoint4d function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via crafted two-dimensional graphics data that is mishandled during clipping-region calculations.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-8vfr-cjhj-gw7x

Mozilla Firefox allows remote attackers to cause a denial of service (crash) via crafted image, as demonstrated by the zzuf lol-firefox.gif test case.

1%
Низкий
почти 4 года назад
github логотип
GHSA-8vcf-c8hj-wp5r

Mozilla Firefox 2.0.0.2 allows remote attackers to spoof the address bar, favicons, and document source, and perform updates in the context of arbitrary websites, by repeatedly setting document.location in the onunload attribute when linking to another website, a variant of CVE-2007-1092.

1%
Низкий
почти 4 года назад

Уязвимостей на страницу