Записи Mozilla
3 824 опубликованных записей вендора mozilla.
Профиль для исследователя
- Попали в KEV
- 15 · 0,4 %
- С эксплойтом
- 39 · 1 %
- Pre-auth RCE
- 1 052
- С записью об исправлении
- 67,7 %
- Медиана: публикация → KEV
- 611 дн.
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer423
- CWE-416 Use After Free302
- CWE-787 Out-of-bounds Write202
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')202
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor198
- CWE-20 Improper Input Validation170
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
3 824 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
95Срочно | CVE-2023-4863Готовый эксплойт | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Высокая8,8 | KEV | 100,0 % | 12 сент. 2023 г. |
94Срочно | CVE-2010-3765Готовый эксплойт | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x befmozilla · firefox · CWE-119 | Критическая9,8 | KEV | 83,2 % | 27 окт. 2010 г. |
87Срочно | CVE-2019-11708Готовый эксплойт | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxemozilla · firefox · CWE-20 | Критическая10,0 | KEV | 55,9 % | 23 июл. 2019 г. |
86Срочно | CVE-2016-9079Готовый эксплойт | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | Высокая7,5 | KEV | 87,4 % | 11 июн. 2018 г. |
86Срочно | CVE-2013-1690Готовый эксплойт | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | Высокая8,8 | KEV | 69,0 % | 25 июн. 2013 г. |
86Срочно | CVE-2015-4495Готовый эксплойт | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | Высокая8,8 | KEV | 68,6 % | 7 авг. 2015 г. |
80Срочно | CVE-2023-5217Готовый эксплойт | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potengoogle · chrome · CWE-787 | Высокая8,8 | KEV | 49,0 % | 28 сент. 2023 г. |
79На этой неделе | CVE-2019-17026Готовый эксплойт | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.mozilla · firefox · CWE-843 | Высокая8,8 | KEV | 46,3 % | 2 мар. 2020 г. |
76На этой неделе | CVE-2019-11707Готовый эксплойт | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.mozilla · firefox · CWE-843 | Высокая8,8 | KEV | 37,7 % | 23 июл. 2019 г. |
76На этой неделе | CVE-2024-9680Готовый эксплойт | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.mozilla · firefox · CWE-416 | Критическая9,8 | KEV | 23,2 % | 9 окт. 2024 г. |
69На этой неделе | CVE-2022-26485Готовый эксплойт | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.mozilla · firefox · CWE-416 | Высокая8,8 | KEV | 14,3 % | 22 дек. 2022 г. |
69На этой неделе | CVE-2022-26486Готовый эксплойт | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.mozilla · firefox · CWE-416 | Критическая9,6 | KEV | 2,3 % | 22 дек. 2022 г. |
65На этой неделе | CVE-2009-3555Proof of concept | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Критическая9,8 | — | 87,3 % | 9 нояб. 2009 г. |
64На этой неделе | CVE-2014-1511Готовый эксплойт | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypamozilla · firefox · CWE-269 | Критическая9,8 | — | 83,6 % | 19 мар. 2014 г. |
64На этой неделе | CVE-2014-1510Готовый эксплойт | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 mozilla · firefox · CWE-269 | Критическая9,8 | — | 82,3 % | 19 мар. 2014 г. |
64На этой неделе | CVE-2020-6820Готовый эксплойт | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | Высокая8,1 | KEV | 7,1 % | 24 апр. 2020 г. |
63На этой неделе | CVE-2011-2371Готовый эксплойт | Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMmozilla · seamonkey · CWE-189 | Критическая10,0 | — | 75,7 % | 30 июн. 2011 г. |
63На этой неделе | CVE-2020-6819Готовый эксплойт | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | Высокая8,1 | KEV | 3,0 % | 24 апр. 2020 г. |
62На этой неделе | CVE-2011-0065Готовый эксплойт | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers mozilla · firefox · CWE-399 | Критическая10,0 | — | 73,8 % | 7 мая 2011 г. |
61На этой неделе | CVE-2011-0073Готовый эксплойт | Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, whichmozilla · firefox · CWE-20 | Критическая10,0 | — | 70,2 % | 7 мая 2011 г. |
59В плане | CVE-2013-0758Готовый эксплойт | Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before mozilla · firefox · CWE-94 | Критическая9,3 | — | 73,4 % | 13 янв. 2013 г. |
58В плане | CVE-2013-1675Готовый эксплойт | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not propermozilla · firefox · CWE-665 | Средняя6,5 | KEV | 6,7 % | 16 мая 2013 г. |
56В плане | CVE-2024-4367Proof of concept | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.mozilla · firefox · CWE-754 | Высокая8,8 | — | 70,7 % | 14 мая 2024 г. |
55В плане | CVE-2013-0757Готовый эксплойт | The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thmozilla · firefox · CWE-20 | Критическая9,3 | — | 60,9 % | 13 янв. 2013 г. |
54В плане | CVE-2006-3677Готовый эксплойт | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain propertimozilla · firefox · CWE-16 | Высокая7,5 | — | 78,7 % | 27 июл. 2006 г. |
- CVE-2023-486395Срочно
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %google · chrome12 сент. 2023 г.
- CVE-2010-376594Срочно
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %mozilla · firefox27 окт. 2010 г.
- CVE-2019-1170887Срочно
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxe
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 56 %mozilla · firefox23 июл. 2019 г.
- CVE-2016-907986Срочно
A use-after-free vulnerability in SVG Animation has been discovered.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 87 %debian · debian linux11 июн. 2018 г.
- CVE-2013-169086Срочно
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %mozilla · firefox25 июн. 2013 г.
- CVE-2015-449586Срочно
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 69 %mozilla · firefox7 авг. 2015 г.
- CVE-2023-521780Срочно
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 49 %google · chrome28 сент. 2023 г.
- CVE-2019-1702679На этой неделе
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 46 %mozilla · firefox2 мар. 2020 г.
- CVE-2019-1170776На этой неделе
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 38 %mozilla · firefox23 июл. 2019 г.
- CVE-2024-968076На этой неделе
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 23 %mozilla · firefox9 окт. 2024 г.
- CVE-2022-2648569На этой неделе
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 14 %mozilla · firefox22 дек. 2022 г.
- CVE-2022-2648669На этой неделе
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.
КритическаяCVSS 9,6KEVГотовый эксплойтEPSS 2 %mozilla · firefox22 дек. 2022 г.
- CVE-2009-355565На этой неделе
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
КритическаяCVSS 9,8Proof of conceptEPSS 87 %apache · http server9 нояб. 2009 г.
- CVE-2014-151164На этой неделе
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa
КритическаяCVSS 9,8Готовый эксплойтEPSS 84 %mozilla · firefox19 мар. 2014 г.
- CVE-2014-151064На этой неделе
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25
КритическаяCVSS 9,8Готовый эксплойтEPSS 82 %mozilla · firefox19 мар. 2014 г.
- CVE-2020-682064На этой неделе
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 7 %mozilla · firefox24 апр. 2020 г.
- CVE-2011-237163На этой неделе
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM
КритическаяCVSS 10,0Готовый эксплойтEPSS 76 %mozilla · seamonkey30 июн. 2011 г.
- CVE-2020-681963На этой неделе
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 3 %mozilla · firefox24 апр. 2020 г.
- CVE-2011-006562На этой неделе
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers
КритическаяCVSS 10,0Готовый эксплойтEPSS 74 %mozilla · firefox7 мая 2011 г.
- CVE-2011-007361На этой неделе
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which
КритическаяCVSS 10,0Готовый эксплойтEPSS 70 %mozilla · firefox7 мая 2011 г.
- CVE-2013-075859В плане
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before
КритическаяCVSS 9,3Готовый эксплойтEPSS 73 %mozilla · firefox13 янв. 2013 г.
- CVE-2013-167558В плане
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 7 %mozilla · firefox16 мая 2013 г.
- CVE-2024-436756В плане
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
ВысокаяCVSS 8,8Proof of conceptEPSS 71 %mozilla · firefox14 мая 2024 г.
- CVE-2013-075755В плане
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Th
КритическаяCVSS 9,3Готовый эксплойтEPSS 61 %mozilla · firefox13 янв. 2013 г.
- CVE-2006-367754В плане
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti
ВысокаяCVSS 7,5Готовый эксплойтEPSS 79 %mozilla · firefox27 июл. 2006 г.