Логотип exploitDog
bind:"CVE-2015-4497" OR bind:"CVE-2015-4498"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2015-4497" OR bind:"CVE-2015-4498"

Количество 15

Количество 15

suse-cvrf логотип

SUSE-SU-2015:1504-1

почти 10 лет назад

Security update for MozillaFirefox

EPSS: Низкий
oracle-oval логотип

ELSA-2015-1693

около 10 лет назад

ELSA-2015-1693: firefox security update (CRITICAL)

EPSS: Низкий
ubuntu логотип

CVE-2015-4498

почти 10 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
EPSS: Низкий
redhat логотип

CVE-2015-4498

около 10 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 5.1
EPSS: Низкий
nvd логотип

CVE-2015-4498

почти 10 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
EPSS: Низкий
debian логотип

CVE-2015-4498

почти 10 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and F ...

CVSS2: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2015-4497

почти 10 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
EPSS: Низкий
redhat логотип

CVE-2015-4497

около 10 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 6.8
EPSS: Низкий
nvd логотип

CVE-2015-4497

почти 10 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
EPSS: Низкий
debian логотип

CVE-2015-4497

почти 10 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implement ...

CVSS2: 10
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2015:1476-1

почти 10 лет назад

Security update for MozillaFirefox, mozilla-nss

EPSS: Низкий
github логотип

GHSA-v9wp-mjxj-3vqc

больше 3 лет назад

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

EPSS: Низкий
github логотип

GHSA-9xmm-8mw4-qgc6

больше 3 лет назад

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

EPSS: Низкий
fstec логотип

BDU:2015-11312

около 10 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю обойти процедуру подтверждения действий пользователем при установке обновления

CVSS2: 7.5
EPSS: Низкий
fstec логотип

BDU:2015-11311

около 10 лет назад

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
suse-cvrf логотип
SUSE-SU-2015:1504-1

Security update for MozillaFirefox

почти 10 лет назад
oracle-oval логотип
ELSA-2015-1693

ELSA-2015-1693: firefox security update (CRITICAL)

около 10 лет назад
ubuntu логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
redhat логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 5.1
1%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-4498

The add-on installation feature in Mozilla Firefox before 40.0.3 and F ...

CVSS2: 7.5
1%
Низкий
почти 10 лет назад
ubuntu логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
3%
Низкий
почти 10 лет назад
redhat логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 6.8
3%
Низкий
около 10 лет назад
nvd логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

CVSS2: 10
3%
Низкий
почти 10 лет назад
debian логотип
CVE-2015-4497

Use-after-free vulnerability in the CanvasRenderingContext2D implement ...

CVSS2: 10
3%
Низкий
почти 10 лет назад
suse-cvrf логотип
SUSE-SU-2015:1476-1

Security update for MozillaFirefox, mozilla-nss

почти 10 лет назад
github логотип
GHSA-v9wp-mjxj-3vqc

Use-after-free vulnerability in the CanvasRenderingContext2D implementation in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to execute arbitrary code by leveraging improper interaction between resize events and changes to Cascading Style Sheets (CSS) token sequences for a CANVAS element.

3%
Низкий
больше 3 лет назад
github логотип
GHSA-9xmm-8mw4-qgc6

The add-on installation feature in Mozilla Firefox before 40.0.3 and Firefox ESR 38.x before 38.2.1 allows remote attackers to bypass an intended user-confirmation requirement by constructing a crafted data: URL and triggering navigation to an arbitrary http: or https: URL at a certain early point in the installation process.

1%
Низкий
больше 3 лет назад
fstec логотип
BDU:2015-11312

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю обойти процедуру подтверждения действий пользователем при установке обновления

CVSS2: 7.5
1%
Низкий
около 10 лет назад
fstec логотип
BDU:2015-11311

Уязвимость браузеров Firefox и Firefox ESR, позволяющая нарушителю выполнить произвольный код

CVSS2: 10
3%
Низкий
около 10 лет назад

Уязвимостей на страницу