Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 17 208

Количество 17 208

github логотип

GHSA-wmph-fgw4-55rj

больше 3 лет назад

If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*<br>*Note*: Due to a clerical error this advisory was not included in the original announcement, and was added in Feburary 2022. This vulnerability affects Firefox < 92.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wmp9-284v-m552

около 4 лет назад

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.

EPSS: Низкий
github логотип

GHSA-wm33-w546-hfhw

около 4 лет назад

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

EPSS: Низкий
github логотип

GHSA-wjv8-8vf9-mrv8

10 месяцев назад

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-wjq6-6xvc-xr82

больше 1 года назад

On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-whq9-vwxq-6f23

больше 2 лет назад

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content.

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-wh9h-xpmv-wgch

около 4 лет назад

Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 51.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-wh8c-356j-pj63

около 4 лет назад

Buffer overflow in the rx::TextureStorage11 class in ANGLE, as used in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted texture data.

EPSS: Низкий
github логотип

GHSA-wh67-cc45-g7cf

почти 2 года назад

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-wgxw-w75w-6fm4

около 4 лет назад

** DISPUTED ** Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been disputed by several vendors, who could not reproduce the report. In addition, the scope of the impact - system freeze - suggests an issue that is not related to Firefox. Due to this impact, CVE concurs with the dispute.

EPSS: Низкий
github логотип

GHSA-wg6h-56g7-mfvv

больше 4 лет назад

Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets

EPSS: Низкий
github логотип

GHSA-wfq5-5w67-p795

около 4 лет назад

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-wfjp-wqgq-35g7

около 4 лет назад

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wfgh-93p3-fwf9

около 4 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 66.

EPSS: Низкий
github логотип

GHSA-wfg4-ch6c-86g5

около 4 лет назад

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

EPSS: Низкий
github логотип

GHSA-wffm-6f65-w6fm

около 4 лет назад

Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META element in cases of context-menu navigation and middle-click navigation, which allows remote attackers to obtain sensitive information by reading web-server Referer logs that contain private data in a URL, as demonstrated by a private path component.

EPSS: Низкий
github логотип

GHSA-wchf-965x-6qj3

около 4 лет назад

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.

EPSS: Низкий
github логотип

GHSA-wc2c-7f6v-vhf3

9 дней назад

Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-w9cf-85vm-mch5

около 4 лет назад

When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-w9c7-gp5q-hh44

около 4 лет назад

An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-wmph-fgw4-55rj

If a domain name contained a RTL character, it would cause the domain to be rendered to the right of the path. This could lead to user confusion and spoofing attacks. <br>*This bug only affects Firefox for Android. Other operating systems are unaffected.*<br>*Note*: Due to a clerical error this advisory was not included in the original announcement, and was added in Feburary 2022. This vulnerability affects Firefox < 92.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-wmp9-284v-m552

updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.

0%
Низкий
около 4 лет назад
github логотип
GHSA-wm33-w546-hfhw

A hyperlink using protocols associated with Internet Explorer, such as IE.HTTP:, can be used to open local files at a known location with Internet Explorer if a user approves execution when prompted. *Note: this issue only occurs on Windows. Other operating systems are unaffected.*. This vulnerability affects Firefox < 67.0.2.

1%
Низкий
около 4 лет назад
github логотип
GHSA-wjv8-8vf9-mrv8

The Firefox and Firefox Focus UI for the Android custom tab feature only showed the "site" that was loaded, not the full hostname. User supplied content hosted on a subdomain of a site could have been used to fool a user into thinking it was content from a different subdomain of that site. This vulnerability affects Firefox < 144.

CVSS3: 8.1
0%
Низкий
10 месяцев назад
github логотип
GHSA-wjq6-6xvc-xr82

On Android, Firefox may have inadvertently allowed viewing saved passwords without the required device PIN authentication. This vulnerability affects Firefox < 133.

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-whq9-vwxq-6f23

When a user scans a QR Code with the QR Code Scanner feature, the user is not prompted before being navigated to the page specified in the code. This may surprise the user and potentially direct them to unwanted content.

CVSS3: 6.1
0%
Низкий
больше 2 лет назад
github логотип
GHSA-wh9h-xpmv-wgch

Memory safety bugs were reported in Firefox 50.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 51.

CVSS3: 9.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-wh8c-356j-pj63

Buffer overflow in the rx::TextureStorage11 class in ANGLE, as used in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4, allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via crafted texture data.

3%
Низкий
около 4 лет назад
github логотип
GHSA-wh67-cc45-g7cf

Opening an external link to an HTTP website when Firefox iOS was previously closed and had an HTTPS tab open could in some cases result in the padlock icon showing an HTTPS indicator incorrectly This vulnerability affects Firefox for iOS < 131.2.

CVSS3: 9.1
0%
Низкий
почти 2 года назад
github логотип
GHSA-wgxw-w75w-6fm4

** DISPUTED ** Firefox 1.5.0.7 on Kubuntu Linux allows remote attackers to cause a denial of service (crash) via a long URL in an A tag. NOTE: this issue has been disputed by several vendors, who could not reproduce the report. In addition, the scope of the impact - system freeze - suggests an issue that is not related to Firefox. Due to this impact, CVE concurs with the dispute.

2%
Низкий
около 4 лет назад
github логотип
GHSA-wg6h-56g7-mfvv

Mozilla Firefox before 3.6 is vulnerable to XSS via the rendering of Cascading Style Sheets

1%
Низкий
больше 4 лет назад
github логотип
GHSA-wfq5-5w67-p795

Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 preserve the network connection used for favicon resource retrieval after the associated browser window is closed, which makes it easier for remote web servers to track users by observing network traffic from multiple IP addresses.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-wfjp-wqgq-35g7

Android intent URLs given to Firefox for Android can be used to navigate from HTTP or HTTPS URLs to local "file:" URLs, allowing for the reading of local data through a violation of same-origin policy. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 54.

CVSS3: 7.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-wfgh-93p3-fwf9

Mozilla developers and community members reported memory safety bugs present in Firefox 65. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 66.

1%
Низкий
около 4 лет назад
github логотип
GHSA-wfg4-ch6c-86g5

Mozilla Firefox before 41.0 allows remote attackers to bypass certain ECMAScript 5 (aka ES5) API protection mechanisms and modify immutable properties, and consequently execute arbitrary JavaScript code with chrome privileges, via a crafted web page that does not use ES5 APIs.

3%
Низкий
около 4 лет назад
github логотип
GHSA-wffm-6f65-w6fm

Mozilla Firefox before 38.0 does not recognize a referrer policy delivered by a referrer META element in cases of context-menu navigation and middle-click navigation, which allows remote attackers to obtain sensitive information by reading web-server Referer logs that contain private data in a URL, as demonstrated by a private path component.

2%
Низкий
около 4 лет назад
github логотип
GHSA-wchf-965x-6qj3

Cross-site scripting (XSS) vulnerability in Mozilla Firefox before 2.0.0.5 allows remote attackers to inject arbitrary web script "into another site's context" via a "timing issue" involving the (1) addEventListener or (2) setTimeout function, probably by setting events that activate after the context has changed.

1%
Низкий
около 4 лет назад
github логотип
GHSA-wc2c-7f6v-vhf3

Clickjacking issue in the WebExtensions component in Firefox for Android. This vulnerability was fixed in Firefox 153.

CVSS3: 6.5
0%
Низкий
9 дней назад
github логотип
GHSA-w9cf-85vm-mch5

When packets with a mismatched RTP payload type are sent in WebRTC connections, in some circumstances a potentially exploitable crash is triggered. This vulnerability affects Firefox ESR < 52.7 and Firefox < 59.

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-w9c7-gp5q-hh44

An attack using manipulation of "updater.ini" contents, used by the Mozilla Windows Updater, and privilege escalation through the Mozilla Maintenance Service to allow for arbitrary file execution and deletion by the Maintenance Service, which has privileged access. Note: This attack requires local system access and only affects Windows. Other operating systems are not affected. This vulnerability affects Firefox ESR < 52.2 and Firefox < 54.

CVSS3: 7.8
0%
Низкий
около 4 лет назад

Уязвимостей на страницу