Логотип exploitDog
product: "firefox"
Консоль
Логотип exploitDog

exploitDog

product: "firefox"

Количество 15 501

Количество 15 501

github логотип

GHSA-7f3m-mqm5-5x2c

8 месяцев назад

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7cgj-mr4w-j8w6

4 месяца назад

This vulnerability affects Firefox < 143.0.3.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-7c9h-gj9v-x83c

почти 4 года назад

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

EPSS: Низкий
github логотип

GHSA-79x3-rj66-524h

больше 3 лет назад

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-79f9-29qm-cx67

больше 3 лет назад

A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-7926-phm6-wvh3

больше 3 лет назад

Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.

EPSS: Низкий
github логотип

GHSA-78p9-f5p7-3p6q

почти 4 года назад

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."

EPSS: Средний
github логотип

GHSA-78mc-5g34-3h4m

больше 3 лет назад

Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.

EPSS: Низкий
github логотип

GHSA-78h7-72xw-23vg

больше 3 лет назад

The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.

EPSS: Низкий
github логотип

GHSA-7873-qcmm-76jc

больше 2 лет назад

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-77wh-39r6-7gg9

больше 3 лет назад

A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction. This could be used to open new tabs in a denial of service (DOS) attack or to display unwanted content from arbitrary URLs to users. This vulnerability affects Firefox < 59.

CVSS3: 8.2
EPSS: Низкий
github логотип

GHSA-77q8-crvw-8w9q

больше 3 лет назад

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

EPSS: Низкий
github логотип

GHSA-77mp-cm2p-44gj

больше 2 лет назад

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-7785-cqjm-vp4q

больше 3 лет назад

When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-764w-vr4w-hf3x

больше 3 лет назад

Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 76.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-75p5-w5j4-v8qj

3 месяца назад

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-7526-6xhc-xh2w

около 3 лет назад

During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-748v-pxm5-9m8q

около 3 лет назад

Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

CVSS3: 3.3
EPSS: Низкий
github логотип

GHSA-73hr-36wp-4xmc

больше 3 лет назад

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-737f-pfm5-cmq6

около 3 лет назад

If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the <code>ThirdPartyUtil</code> component. This vulnerability affects Firefox < 106.

CVSS3: 7.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-7f3m-mqm5-5x2c

If a user visited a webpage with an invalid TLS certificate, and granted an exception, the webpage was able to provide a WebAuthn challenge that the user would be prompted to complete. This is in violation of the WebAuthN spec which requires "a secure transport established without errors". This vulnerability affects Firefox < 140.

CVSS3: 9.8
0%
Низкий
8 месяцев назад
github логотип
GHSA-7cgj-mr4w-j8w6

This vulnerability affects Firefox < 143.0.3.

CVSS3: 7.5
0%
Низкий
4 месяца назад
github логотип
GHSA-7c9h-gj9v-x83c

A flaw in Mozilla's embedded certificate code might allow web sites to install root certificates on devices without user approval.

0%
Низкий
почти 4 года назад
github логотип
GHSA-79x3-rj66-524h

Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 mishandle a navigation sequence that returns to the original page, which allows remote attackers to spoof the address bar via vectors involving the history.back method and the location.protocol property.

CVSS3: 4.3
1%
Низкий
больше 3 лет назад
github логотип
GHSA-79f9-29qm-cx67

A heap buffer overflow vulnerability may occur in WebAssembly during Memory/Table resizing, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 58.

CVSS3: 7.5
35%
Средний
больше 3 лет назад
github логотип
GHSA-7926-phm6-wvh3

Firefox for Android allowed navigations through the `intent://` protocol, which could be used to cause crashes and UI spoofs. *This bug only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox < 92.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-78p9-f5p7-3p6q

The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a large value in the r (aka Radius) attribute of a circle element, related to an "unclamped loop."

12%
Средний
почти 4 года назад
github логотип
GHSA-78mc-5g34-3h4m

Race condition in the JPEGEncoder function in Mozilla Firefox before 42.0 and Firefox ESR 38.x before 38.4 allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow) via vectors involving a CANVAS element and crafted JavaScript code.

4%
Низкий
больше 3 лет назад
github логотип
GHSA-78h7-72xw-23vg

The nsTArray_Impl class in Mozilla Firefox before 40.0, Firefox ESR 38.x before 38.2, and Firefox OS before 2.2 might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging a self assignment.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-7873-qcmm-76jc

In a non-standard configuration of Firefox, an integer overflow could have occurred based on network traffic (possibly under influence of a local unprivileged webpage), leading to an out-of-bounds write to privileged process memory. *This bug only affects Firefox if a non-standard preference allowing non-HTTPS Alternate Services (`network.http.altsvc.oe`) is enabled.* This vulnerability affects Firefox < 118.

CVSS3: 7.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-77wh-39r6-7gg9

A vulnerability in the notifications Push API where notifications can be sent through service workers by web content without direct user interaction. This could be used to open new tabs in a denial of service (DOS) attack or to display unwanted content from arbitrary URLs to users. This vulnerability affects Firefox < 59.

CVSS3: 8.2
1%
Низкий
больше 3 лет назад
github логотип
GHSA-77q8-crvw-8w9q

When a HTTPS pages was embedded in a HTTP page, and there was a service worker registered for the former, the service worker could have intercepted the request for the secure page despite the iframe not being a secure context due to the (insecure) framing. This vulnerability affects Firefox < 84.

2%
Низкий
больше 3 лет назад
github логотип
GHSA-77mp-cm2p-44gj

When dragging and dropping an image cross-origin, the image's size could potentially be leaked. This behavior was shipped in 109 and caused web compatibility problems as well as this security concern, so the behavior was disabled until further review. This vulnerability affects Firefox < 110.

CVSS3: 6.5
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7785-cqjm-vp4q

When arbitrary text is sent over an FTP connection and a page reload is initiated, it is possible to create a modal alert message with this text as the content. This could potentially be used for social engineering attacks. This vulnerability affects Firefox < 66.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-764w-vr4w-hf3x

Mozilla developers and community members reported memory safety bugs present in Firefox 75. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 76.

CVSS3: 9.8
1%
Низкий
больше 3 лет назад
github логотип
GHSA-75p5-w5j4-v8qj

Incorrect boundary conditions in the Graphics: WebGPU component. This vulnerability affects Firefox < 145.

CVSS3: 9.8
0%
Низкий
3 месяца назад
github логотип
GHSA-7526-6xhc-xh2w

During startup, a graphics driver with an unexpected name could lead to a stack-buffer overflow causing a potentially exploitable crash.<br>*This issue only affects Firefox for Android. Other operating systems are not affected.*. This vulnerability affects Firefox < 105.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-748v-pxm5-9m8q

Logins saved by Firefox should be managed by the Password Manager component which uses encryption to save files on-disk. Instead, the username (not password) was saved by the Form Manager to an unencrypted file on disk. This vulnerability affects Firefox < 106.

CVSS3: 3.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-73hr-36wp-4xmc

Mozilla Firefox before 46.0 on Android before 5.0 allows attackers to bypass intended Signature access requirements via a crafted application that leverages content-provider permissions, as demonstrated by reading the browser history or a saved password.

CVSS3: 5
0%
Низкий
больше 3 лет назад
github логотип
GHSA-737f-pfm5-cmq6

If two Workers were simultaneously initializing their CacheStorage, a data race could have occurred in the <code>ThirdPartyUtil</code> component. This vulnerability affects Firefox < 106.

CVSS3: 7.1
0%
Низкий
около 3 лет назад

Уязвимостей на страницу