İçeriğe atla
Noroxi

mozilla kayıtları

mozilla üreticisine ait 3.824 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
15 · %0,4
Silahlaştırılmış
39 · %1
Pre-auth RCE
1.052
Düzeltme kaydı olan
%67,7
Yayından KEV’e ortanca
611 gün

Tüm kayıtlar

3.824 kayıt
  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100

    google · chrome12 Eyl 2023

  • Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %83

    mozilla · firefox27 Eki 2010

  • Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxe

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %56

    mozilla · firefox23 Tem 2019

  • A use-after-free vulnerability in SVG Animation has been discovered.

    YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %87

    debian · debian linux11 Haz 2018

  • Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69

    mozilla · firefox25 Haz 2013

  • The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69

    mozilla · firefox7 Ağu 2015

  • Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49

    google · chrome28 Eyl 2023

  • CVE-2019-17026
    79Bu hafta

    Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %46

    mozilla · firefox2 Mar 2020

  • CVE-2019-11707
    76Bu hafta

    A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %38

    mozilla · firefox23 Tem 2019

  • CVE-2024-9680
    76Bu hafta

    An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %23

    mozilla · firefox9 Eki 2024

  • CVE-2022-26485
    69Bu hafta

    Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.

    YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %14

    mozilla · firefox22 Ara 2022

  • CVE-2022-26486
    69Bu hafta

    An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.

    KritikCVSS 9,6KEVSilahlaştırılmışEPSS %2

    mozilla · firefox22 Ara 2022

  • CVE-2009-3555
    65Bu hafta

    The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th

    KritikCVSS 9,8Kavram kanıtıEPSS %87

    apache · http server9 Kas 2009

  • CVE-2014-1511
    64Bu hafta

    Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa

    KritikCVSS 9,8SilahlaştırılmışEPSS %84

    mozilla · firefox19 Mar 2014

  • CVE-2014-1510
    64Bu hafta

    The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25

    KritikCVSS 9,8SilahlaştırılmışEPSS %82

    mozilla · firefox19 Mar 2014

  • CVE-2020-6820
    64Bu hafta

    Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %7

    mozilla · firefox24 Nis 2020

  • CVE-2011-2371
    63Bu hafta

    Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM

    KritikCVSS 10,0SilahlaştırılmışEPSS %76

    mozilla · seamonkey30 Haz 2011

  • CVE-2020-6819
    63Bu hafta

    Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.

    YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %3

    mozilla · firefox24 Nis 2020

  • CVE-2011-0065
    62Bu hafta

    Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers

    KritikCVSS 10,0SilahlaştırılmışEPSS %74

    mozilla · firefox7 May 2011

  • CVE-2011-0073
    61Bu hafta

    Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which

    KritikCVSS 10,0SilahlaştırılmışEPSS %70

    mozilla · firefox7 May 2011

  • CVE-2013-0758
    59Planlayın

    Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before

    KritikCVSS 9,3SilahlaştırılmışEPSS %73

    mozilla · firefox13 Oca 2013

  • CVE-2013-1675
    58Planlayın

    Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper

    OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %7

    mozilla · firefox16 May 2013

  • CVE-2024-4367
    56Planlayın

    A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.

    YüksekCVSS 8,8Kavram kanıtıEPSS %71

    mozilla · firefox14 May 2024

  • CVE-2013-0757
    55Planlayın

    The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Th

    KritikCVSS 9,3SilahlaştırılmışEPSS %61

    mozilla · firefox13 Oca 2013

  • CVE-2006-3677
    54Planlayın

    Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti

    YüksekCVSS 7,5SilahlaştırılmışEPSS %79

    mozilla · firefox27 Tem 2006