Логотип exploitDog
bind:"CVE-2014-8634" OR bind:"CVE-2014-8639" OR bind:"CVE-2014-8638"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2014-8634" OR bind:"CVE-2014-8639" OR bind:"CVE-2014-8638"

Количество 17

Количество 17

oracle-oval логотип

ELSA-2015-0047

больше 10 лет назад

ELSA-2015-0047: thunderbird security update (IMPORTANT)

EPSS: Низкий
oracle-oval логотип

ELSA-2015-0046

больше 10 лет назад

ELSA-2015-0046: firefox security and bug fix update (CRITICAL)

EPSS: Низкий
ubuntu логотип

CVE-2014-8634

больше 10 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2014-8634

больше 10 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2014-8634

больше 10 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2014-8634

больше 10 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 7.5
EPSS: Низкий
github логотип

GHSA-hhxf-vm3m-cxrp

больше 3 лет назад

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

EPSS: Низкий
ubuntu логотип

CVE-2014-8639

больше 10 лет назад

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2014-8639

больше 10 лет назад

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-8639

больше 10 лет назад

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-8639

больше 10 лет назад

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird ...

CVSS2: 6.8
EPSS: Низкий
ubuntu логотип

CVE-2014-8638

больше 10 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 6.8
EPSS: Низкий
redhat логотип

CVE-2014-8638

больше 10 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-8638

больше 10 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 6.8
EPSS: Низкий
debian логотип

CVE-2014-8638

больше 10 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0 ...

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-cfgr-xpqw-rcxf

больше 3 лет назад

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

EPSS: Низкий
github логотип

GHSA-38xr-6jm2-v69w

больше 3 лет назад

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
oracle-oval логотип
ELSA-2015-0047

ELSA-2015-0047: thunderbird security update (IMPORTANT)

больше 10 лет назад
oracle-oval логотип
ELSA-2015-0046

ELSA-2015-0046: firefox security and bug fix update (CRITICAL)

больше 10 лет назад
ubuntu логотип
CVE-2014-8634

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 7.5
1%
Низкий
больше 10 лет назад
redhat логотип
CVE-2014-8634

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-8634

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVSS2: 7.5
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-8634

Multiple unspecified vulnerabilities in the browser engine in Mozilla ...

CVSS2: 7.5
1%
Низкий
больше 10 лет назад
github логотип
GHSA-hhxf-vm3m-cxrp

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
redhat логотип
CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 4.3
1%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-8639

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird ...

CVSS2: 6.8
1%
Низкий
больше 10 лет назад
ubuntu логотип
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
redhat логотип
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 4.3
0%
Низкий
больше 10 лет назад
nvd логотип
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
debian логотип
CVE-2014-8638

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0 ...

CVSS2: 6.8
0%
Низкий
больше 10 лет назад
github логотип
GHSA-cfgr-xpqw-rcxf

Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 do not properly interpret Set-Cookie headers within responses that have a 407 (aka Proxy Authentication Required) status code, which allows remote HTTP proxy servers to conduct session fixation attacks by providing a cookie name that corresponds to the session cookie of the origin server.

1%
Низкий
больше 3 лет назад
github логотип
GHSA-38xr-6jm2-v69w

The navigator.sendBeacon implementation in Mozilla Firefox before 35.0, Firefox ESR 31.x before 31.4, Thunderbird before 31.4, and SeaMonkey before 2.32 omits the CORS Origin header, which allows remote attackers to bypass intended CORS access-control checks and conduct cross-site request forgery (CSRF) attacks via a crafted web site.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу