Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 14 599

Количество 14 599

github логотип

GHSA-wfjp-wqgq-35g7

около 3 лет назад

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wfgh-93p3-fwf9

около 3 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 66.

EPSS: Низкий
github логотип

GHSA-wfg4-ch6c-86g5

около 3 лет назад

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

EPSS: Низкий
github логотип

GHSA-wffm-6f65-w6fm

около 3 лет назад

Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META element in cases of context-menu navigation and middle-click navigation, which allows remote attackers to obtain sensitive information by reading web-server Referer logs that contain private data in a URL, as demonstrated by a private path component.

EPSS: Низкий
github логотип

GHSA-wchf-965x-6qj3

около 3 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.

EPSS: Низкий
github логотип

GHSA-w96m-wgv7-3r86

почти 2 года назад

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-w92w-fc6m-j79x

около 3 лет назад

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w8qx-wh3f-f42p

около 3 лет назад

Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

EPSS: Низкий
github логотип

GHSA-w8ph-2788-7wg9

около 3 лет назад

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

EPSS: Низкий
github логотип

GHSA-w8p9-p5cr-4q8f

около 3 лет назад

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-w8fm-f723-jm45

около 3 лет назад

Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w7v9-gmfx-55cf

около 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
github логотип

GHSA-w7p9-j7cw-wfpm

около 3 лет назад

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

EPSS: Низкий
github логотип

GHSA-w7mj-jcq9-3g34

около 3 лет назад

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-w757-mvqp-v98h

около 3 лет назад

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

EPSS: Низкий
github логотип

GHSA-w752-w9m4-4289

около 3 лет назад

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-w739-3fq5-fgvp

около 3 лет назад

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

EPSS: Средний
github логотип

GHSA-w6cr-qvrp-w86v

около 3 лет назад

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
EPSS: Низкий
github логотип

GHSA-w694-6mxx-38mc

около 1 года назад

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-w65j-fpvf-v9rw

около 3 лет назад

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wfjp-wqgq-35g7

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-wfgh-93p3-fwf9

Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 66.

0%
Низкий
около 3 лет назад
github логотип
GHSA-wfg4-ch6c-86g5

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

2%
Низкий
около 3 лет назад
github логотип
GHSA-wffm-6f65-w6fm

Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META element in cases of context-menu navigation and middle-click navigation, which allows remote attackers to obtain sensitive information by reading web-server Referer logs that contain private data in a URL, as demonstrated by a private path component.

1%
Низкий
около 3 лет назад
github логотип
GHSA-wchf-965x-6qj3

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.

2%
Низкий
около 3 лет назад
github логотип
GHSA-w96m-wgv7-3r86

A website could have obscured the full screen notification by using the file open dialog. This could have led to user confusion and possible spoofing attacks. This vulnerability affects Firefox < 116.

CVSS3: 7.5
0%
Низкий
почти 2 года назад
github логотип
GHSA-w92w-fc6m-j79x

Use-after-free vulnerability in the ServiceWorkerInfo class in the Service Worker subsystem in Mozilla Firefox before 46.0 allows remote attackers to execute arbitrary code via vectors related to the BeginReading method.

CVSS3: 8.8
2%
Низкий
около 3 лет назад
github логотип
GHSA-w8qx-wh3f-f42p

Mozilla Firefox before 42.0 on Android does not ensure that the address bar is restored upon fullscreen-mode exit, which allows remote attackers to spoof the address bar via crafted JavaScript code.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w8ph-2788-7wg9

Firefox, when opening Microsoft Word documents, does not properly set the permissions on shared sections, which allows remote attackers to write arbitrary data to open applications in Microsoft Office.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w8p9-p5cr-4q8f

Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.

CVSS3: 9.8
4%
Низкий
около 3 лет назад
github логотип
GHSA-w8fm-f723-jm45

Mozilla Firefox before 48.0, Firefox ESR < 45.4 and Thunderbird < 45.4 allow remote attackers to obtain sensitive information about the previously retrieved page via Resource Timing API calls.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-w7v9-gmfx-55cf

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

4%
Низкий
около 3 лет назад
github логотип
GHSA-w7p9-j7cw-wfpm

Mozilla Firefox 3.x before 3.0.4 assigns chrome privileges to a file: URI when it is accessed in the same tab from a chrome or privileged about: page, which makes it easier for user-assisted attackers to execute arbitrary JavaScript with chrome privileges via malicious code in a file that has already been saved on the local system.

6%
Низкий
около 3 лет назад
github логотип
GHSA-w7mj-jcq9-3g34

Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.

CVSS3: 6.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-w757-mvqp-v98h

content/html/document/src/nsHTMLDocument.cpp in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allows user-assisted remote attackers to bypass the Same Origin Policy and read an arbitrary content selection via the document.getSelection function.

0%
Низкий
около 3 лет назад
github логотип
GHSA-w752-w9m4-4289

The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site to socially engineer a user to copy and paste malicious script content that could then run with the context of either page but does not allow for privilege escalation. This vulnerability affects Firefox < 60.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-w739-3fq5-fgvp

Mozilla Firefox before 2.0.0.5 does not prevent use of document.write to replace an IFRAME (1) during the load stage or (2) in the case of an about:blank frame, which allows remote attackers to display arbitrary HTML or execute certain JavaScript code, as demonstrated by code that intercepts keystroke values from window.event, aka the "promiscuous IFRAME access bug," a related issue to CVE-2006-4568.

20%
Средний
около 3 лет назад
github логотип
GHSA-w6cr-qvrp-w86v

The FileReader class in Mozilla Firefox before 45.0 allows local users to gain privileges or cause a denial of service (memory corruption) by changing a file during a FileReader API read operation.

CVSS3: 7.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-w694-6mxx-38mc

A memory allocation check was missing which would lead to a use-after-free if the allocation failed. This could have triggered a crash or potentially be leveraged to achieve code execution. This vulnerability affects Firefox < 126.

CVSS3: 8.6
1%
Низкий
около 1 года назад
github логотип
GHSA-w65j-fpvf-v9rw

Mozilla developers reported memory safety bugs present in Firefox 81. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 82.

0%
Низкий
около 3 лет назад

Уязвимостей на страницу