Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-8rh9-c9p7-ppjc

почти 4 года назад

Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.

EPSS: Средний
github логотип

GHSA-8r38-4g4q-hgvw

7 месяцев назад

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8r32-wxw2-w78f

больше 3 лет назад

The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using an NSAccessibilityIndexAttribute value to reference a row index.

EPSS: Низкий
github логотип

GHSA-8qrw-9ppf-58qg

больше 3 лет назад

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8qqj-ch4p-86p2

почти 4 года назад

Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a link to a data: URI containing an encoded URL. NOTE: the severity of this issue has been disputed by a reliable third party, since the intended functionality of the status bar allows it to be modified.

EPSS: Низкий
github логотип

GHSA-8q64-5xmq-2f45

3 месяца назад

Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and Firefox ESR < 115.30.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-8prr-wp36-5mv2

3 месяца назад

Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-8p3c-2cqq-899r

больше 3 лет назад

Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 55.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-8mxh-558j-w4gm

больше 2 лет назад

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8mhr-8p53-r587

больше 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 77.

EPSS: Низкий
github логотип

GHSA-8mf7-p7xv-mq52

больше 3 лет назад

Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.

EPSS: Низкий
github логотип

GHSA-8jhp-825c-3qwx

больше 3 лет назад

Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.

EPSS: Низкий
github логотип

GHSA-8j8h-gcch-8c79

больше 3 лет назад

Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted GIF image.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8j5m-6wvx-8fqm

больше 3 лет назад

A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8h4g-cp4v-9cg4

больше 3 лет назад

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-8h36-rwvg-grvq

больше 3 лет назад

When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8grv-7wf2-qcqv

больше 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-8g7p-v6f6-52wp

больше 3 лет назад

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level domains, which allows remote attackers to spoof the address bar via unspecified homograph characters.

EPSS: Низкий
github логотип

GHSA-8fm3-gjrc-9963

больше 3 лет назад

The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.

EPSS: Низкий
github логотип

GHSA-8f39-w2xj-cv9f

больше 3 лет назад

Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 59.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8rh9-c9p7-ppjc

Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Javascript that uses the "onunload" method.

18%
Средний
почти 4 года назад
github логотип
GHSA-8r38-4g4q-hgvw

Firefox could have incorrectly parsed a URL and rewritten it to the youtube.com domain when parsing the URL specified in an `embed` tag. This could have bypassed website security checks that restricted which domains users were allowed to embed. This vulnerability affects Firefox < 140 and Firefox ESR < 128.12.

CVSS3: 6.5
0%
Низкий
7 месяцев назад
github логотип
GHSA-8r32-wxw2-w78f

The accessibility-tools feature in Mozilla Firefox before 42.0 on OS X improperly interacts with the implementation of the TABLE element, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by using an NSAccessibilityIndexAttribute value to reference a row index.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-8qrw-9ppf-58qg

When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-8qqj-ch4p-86p2

Mozilla Firefox 2.0.0.6 and earlier allows remote attackers to spoof the contents of the status bar via a link to a data: URI containing an encoded URL. NOTE: the severity of this issue has been disputed by a reliable third party, since the intended functionality of the status bar allows it to be modified.

1%
Низкий
почти 4 года назад
github логотип
GHSA-8q64-5xmq-2f45

Use-after-free in the Audio/Video component. This vulnerability affects Firefox < 145, Firefox ESR < 140.5, and Firefox ESR < 115.30.

CVSS3: 8.8
0%
Низкий
3 месяца назад
github логотип
GHSA-8prr-wp36-5mv2

Same-origin policy bypass in the DOM: Notifications component. This vulnerability affects Firefox < 145 and Firefox ESR < 140.5.

CVSS3: 8.1
0%
Низкий
3 месяца назад
github логотип
GHSA-8p3c-2cqq-899r

Memory safety bugs were reported in Firefox 54. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 55.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-8mxh-558j-w4gm

A website could have obscured the full screen notification by using a URL with a scheme handled by an external program, such as a mailto URL. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-8mhr-8p53-r587

Mozilla developers reported memory safety bugs present in Firefox 76. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 77.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8mf7-p7xv-mq52

Heap-based buffer overflow in the stagefright::ESDS::parseESDescriptor function in libstagefright in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 allows remote attackers to execute arbitrary code via an invalid size field in an esds chunk in MPEG-4 video data, a related issue to CVE-2015-1539.

7%
Низкий
больше 3 лет назад
github логотип
GHSA-8jhp-825c-3qwx

Untrusted search path vulnerability in the installer in Mozilla Firefox before 17.0 and Firefox ESR 10.x before 10.0.11 on Windows allows local users to gain privileges via a Trojan horse DLL in the default downloads directory.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8j8h-gcch-8c79

Integer overflow in the image-deinterlacing functionality in Mozilla Firefox before 44.0 allows remote attackers to cause a denial of service (memory consumption or application crash) via a crafted GIF image.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-8j5m-6wvx-8fqm

A service worker can send the activate event on itself periodically which allows it to run perpetually, allowing it to monitor activity by users. Affects all versions prior to Firefox 60.

CVSS3: 7.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-8h4g-cp4v-9cg4

Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing by an authenticated user on a third-party website. This vulnerability affects Firefox ESR < 52.8 and Firefox < 60.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-8h36-rwvg-grvq

When a user navigates to site marked as unsafe by the Safebrowsing API, warning messages are displayed and navigation is interrupted but resources from the same site loaded through websockets are not blocked, leading to the loading of unsafe resources and bypassing safebrowsing protections. This vulnerability affects Firefox < 68.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-8grv-7wf2-qcqv

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 48.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS3: 8.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-8g7p-v6f6-52wp

The Internationalized Domain Name (IDN) display algorithm in Mozilla Firefox before 22.0 does not properly handle the .com, .name, and .net top-level domains, which allows remote attackers to spoof the address bar via unspecified homograph characters.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8fm3-gjrc-9963

The X.509 certificate validation functionality in Mozilla Firefox 4.0.x through 4.0.1 does not properly implement single-session security exceptions, which might make it easier for user-assisted remote attackers to spoof an SSL server via an untrusted certificate that triggers potentially unwanted local caching of documents from that server.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-8f39-w2xj-cv9f

Memory safety bugs were reported in Firefox 58. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 59.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад

Уязвимостей на страницу