Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-8cxh-33q5-hvj6

почти 4 года назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.

EPSS: Низкий
github логотип

GHSA-8cmq-qrm5-cvxq

больше 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-8c7g-vx5g-cmpg

больше 1 года назад

When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-8c4w-xw52-85px

около 2 лет назад

A `` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-89w9-2j44-v823

почти 4 года назад

The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.

EPSS: Низкий
github логотип

GHSA-89pp-rgcf-3584

больше 3 лет назад

Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 58.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-893r-mpwj-qhhg

больше 1 года назад

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-88rc-c9h4-g333

больше 3 лет назад

A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. This vulnerability allows for spoofing but no scripted content can be run. This vulnerability affects Firefox < 53.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-88qm-q663-fvg2

больше 3 лет назад

The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-88p3-h3gw-7xj6

больше 3 лет назад

When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1.

EPSS: Низкий
github логотип

GHSA-887x-j4cf-3pqh

больше 3 лет назад

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.

CVSS3: 2.8
EPSS: Низкий
github логотип

GHSA-87wr-93m4-5rjf

больше 3 лет назад

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

EPSS: Низкий
github логотип

GHSA-87mm-rg9r-h8wm

7 месяцев назад

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-87c4-94w2-rw7j

7 месяцев назад

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-874r-f6v2-m748

больше 3 лет назад

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-86v9-wc7f-xw96

больше 3 лет назад

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.

EPSS: Низкий
github логотип

GHSA-86rq-87v9-7ppc

больше 3 лет назад

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-86q6-8hr2-487f

6 месяцев назад

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-85vg-hqhq-qvx3

больше 2 лет назад

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-85p8-hpwj-pgv8

больше 3 лет назад

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-8cxh-33q5-hvj6

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.14 and 3.5.x before 3.5.3, Thunderbird before 2.0.0.24, and SeaMonkey before 1.1.19 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to the BinHex decoder in netwerk/streamconv/converters/nsBinHexDecoder.cpp, and unknown vectors.

5%
Низкий
почти 4 года назад
github логотип
GHSA-8cmq-qrm5-cvxq

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 42.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-8c7g-vx5g-cmpg

When manipulating the selection node cache, an attacker may have been able to cause unexpected behavior, potentially leading to an exploitable crash. This vulnerability affects Firefox < 131.0.3.

CVSS3: 6.5
0%
Низкий
больше 1 года назад
github логотип
GHSA-8c4w-xw52-85px

A `` element could have been manipulated to paint content outside of a sandboxed iframe. This could allow untrusted content to display under the guise of trusted content. This vulnerability affects Firefox < 121.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-89w9-2j44-v823

The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.

3%
Низкий
почти 4 года назад
github логотип
GHSA-89pp-rgcf-3584

Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 58.

CVSS3: 9.8
2%
Низкий
больше 3 лет назад
github логотип
GHSA-893r-mpwj-qhhg

In violation of spec, cookie prefixes such as `__Secure` were being ignored if they were not correctly capitalized - by spec they should be checked with a case-insensitive comparison. This could have resulted in the browser not correctly honoring the behaviors specified by the prefix. This vulnerability affects Firefox < 127.

CVSS3: 9.8
1%
Низкий
больше 1 года назад
github логотип
GHSA-88rc-c9h4-g333

A mechanism to inject static HTML into the RSS reader preview page due to a failure to escape characters sent as URL parameters for a feed's "TITLE" element. This vulnerability allows for spoofing but no scripted content can be run. This vulnerability affects Firefox < 53.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-88qm-q663-fvg2

The file-download dialog in Mozilla Firefox before 44.0 on OS X enables a certain button too quickly, which allows remote attackers to conduct clickjacking attacks via a crafted web site that triggers a single-click action in a situation where a double-click action was intended.

CVSS3: 6.1
0%
Низкий
больше 3 лет назад
github логотип
GHSA-88p3-h3gw-7xj6

When drawing text onto a canvas with WebRender disabled, an out of bounds read could occur. *This bug only affects Firefox on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 89.0.1.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-887x-j4cf-3pqh

Initially, a user opens a Private Browsing Window and generates a password for a site, then closes the Private Browsing Window but leaves Firefox open. Subsequently, if the user had opened a new Private Browsing Window, revisited the same site, and generated a new password - the generated passwords would have been identical, rather than independent. This vulnerability affects Firefox < 75.

CVSS3: 2.8
0%
Низкий
больше 3 лет назад
github логотип
GHSA-87wr-93m4-5rjf

Mozilla Firefox before 4 cannot properly restrict modifications to cookies established in HTTPS sessions, which allows man-in-the-middle attackers to overwrite or delete arbitrary cookies via a Set-Cookie header in an HTTP response, related to lack of the HTTP Strict Transport Security (HSTS) includeSubDomains feature, aka a "cookie forcing" issue.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-87mm-rg9r-h8wm

The exception page for the HTTPS-Only feature, displayed when a website is opened via HTTP, lacked an anti-clickjacking delay, potentially allowing an attacker to trick a user into granting an exception and loading a webpage over HTTP. This vulnerability affects Firefox < 140.

CVSS3: 4.3
0%
Низкий
7 месяцев назад
github логотип
GHSA-87c4-94w2-rw7j

A use-after-free in FontFaceSet resulted in a potentially exploitable crash. This vulnerability affects Firefox < 140, Firefox ESR < 115.25, and Firefox ESR < 128.12.

CVSS3: 9.8
0%
Низкий
7 месяцев назад
github логотип
GHSA-874r-f6v2-m748

WebExtensions can bypass security checks to load privileged URLs and potentially escape the WebExtension sandbox. This vulnerability affects Firefox < 50.

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-86v9-wc7f-xw96

The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-86rq-87v9-7ppc

After a HelloRetryRequest has been sent, the client may negotiate a lower protocol that TLS 1.3, resulting in an invalid state transition in the TLS State Machine. If the client gets into this state, incoming Application Data records will be ignored. This vulnerability affects Firefox < 72.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-86q6-8hr2-487f

Firefox for Android allowed a sandboxed iframe without the `allow-downloads` attribute to start downloads. This vulnerability affects Firefox < 141.

CVSS3: 9.8
0%
Низкий
6 месяцев назад
github логотип
GHSA-85vg-hqhq-qvx3

Offscreen Canvas did not properly track cross-origin tainting, which could have been used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 116, Firefox ESR < 102.14, and Firefox ESR < 115.1.

CVSS3: 5.3
0%
Низкий
больше 2 лет назад
github логотип
GHSA-85p8-hpwj-pgv8

The Mozilla Updater in Mozilla Firefox before 21.0 on Windows does not properly maintain Mozilla Maintenance Service registry entries in certain situations involving upgrades from older Firefox versions, which allows local users to gain privileges by leveraging write access to a "trusted path."

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу