mozilla kayıtları
mozilla üreticisine ait 3.824 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 15 · %0,4
- Silahlaştırılmış
- 39 · %1
- Pre-auth RCE
- 1.052
- Düzeltme kaydı olan
- %67,7
- Yayından KEV’e ortanca
- 611 gün
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer423
- CWE-416 Use After Free302
- CWE-787 Out-of-bounds Write202
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')202
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor198
- CWE-20 Improper Input Validation170
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
3.824 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
95Hemen | CVE-2023-4863Silahlaştırılmış | Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bogoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %100,0 | 12 Eyl 2023 |
94Hemen | CVE-2010-3765Silahlaştırılmış | Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x befmozilla · firefox · CWE-119 | Kritik9,8 | KEV | %83,2 | 27 Eki 2010 |
87Hemen | CVE-2019-11708Silahlaştırılmış | Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxemozilla · firefox · CWE-20 | Kritik10,0 | KEV | %55,9 | 23 Tem 2019 |
86Hemen | CVE-2016-9079Silahlaştırılmış | A use-after-free vulnerability in SVG Animation has been discovered.debian · debian linux · CWE-416 | Yüksek7,5 | KEV | %87,4 | 11 Haz 2018 |
86Hemen | CVE-2013-1690Silahlaştırılmış | Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not propermozilla · firefox · CWE-119 | Yüksek8,8 | KEV | %69,0 | 25 Haz 2013 |
86Hemen | CVE-2015-4495Silahlaştırılmış | The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypassmozilla · firefox · CWE-346 | Yüksek8,8 | KEV | %68,6 | 7 Ağu 2015 |
80Hemen | CVE-2023-5217Silahlaştırılmış | Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to potengoogle · chrome · CWE-787 | Yüksek8,8 | KEV | %49,0 | 28 Eyl 2023 |
79Bu hafta | CVE-2019-17026Silahlaştırılmış | Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.mozilla · firefox · CWE-843 | Yüksek8,8 | KEV | %46,3 | 2 Mar 2020 |
76Bu hafta | CVE-2019-11707Silahlaştırılmış | A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.mozilla · firefox · CWE-843 | Yüksek8,8 | KEV | %37,7 | 23 Tem 2019 |
76Bu hafta | CVE-2024-9680Silahlaştırılmış | An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.mozilla · firefox · CWE-416 | Kritik9,8 | KEV | %23,2 | 9 Eki 2024 |
69Bu hafta | CVE-2022-26485Silahlaştırılmış | Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.mozilla · firefox · CWE-416 | Yüksek8,8 | KEV | %14,3 | 22 Ara 2022 |
69Bu hafta | CVE-2022-26486Silahlaştırılmış | An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.mozilla · firefox · CWE-416 | Kritik9,6 | KEV | %2,3 | 22 Ara 2022 |
65Bu hafta | CVE-2009-3555Kavram kanıtı | The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in thapache · http server · CWE-295 | Kritik9,8 | — | %87,3 | 9 Kas 2009 |
64Bu hafta | CVE-2014-1511Silahlaştırılmış | Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypamozilla · firefox · CWE-269 | Kritik9,8 | — | %83,6 | 19 Mar 2014 |
64Bu hafta | CVE-2014-1510Silahlaştırılmış | The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 mozilla · firefox · CWE-269 | Kritik9,8 | — | %82,3 | 19 Mar 2014 |
64Bu hafta | CVE-2020-6820Silahlaştırılmış | Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | Yüksek8,1 | KEV | %7,1 | 24 Nis 2020 |
63Bu hafta | CVE-2011-2371Silahlaştırılmış | Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMmozilla · seamonkey · CWE-189 | Kritik10,0 | — | %75,7 | 30 Haz 2011 |
63Bu hafta | CVE-2020-6819Silahlaştırılmış | Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.mozilla · firefox · CWE-362 | Yüksek8,1 | KEV | %3,0 | 24 Nis 2020 |
62Bu hafta | CVE-2011-0065Silahlaştırılmış | Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers mozilla · firefox · CWE-399 | Kritik10,0 | — | %73,8 | 7 May 2011 |
61Bu hafta | CVE-2011-0073Silahlaştırılmış | Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, whichmozilla · firefox · CWE-20 | Kritik10,0 | — | %70,2 | 7 May 2011 |
59Planlayın | CVE-2013-0758Silahlaştırılmış | Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before mozilla · firefox · CWE-94 | Kritik9,3 | — | %73,4 | 13 Oca 2013 |
58Planlayın | CVE-2013-1675Silahlaştırılmış | Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not propermozilla · firefox · CWE-665 | Orta6,5 | KEV | %6,7 | 16 May 2013 |
56Planlayın | CVE-2024-4367Kavram kanıtı | A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.mozilla · firefox · CWE-754 | Yüksek8,8 | — | %70,7 | 14 May 2024 |
55Planlayın | CVE-2013-0757Silahlaştırılmış | The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Thmozilla · firefox · CWE-20 | Kritik9,3 | — | %60,9 | 13 Oca 2013 |
54Planlayın | CVE-2006-3677Silahlaştırılmış | Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain propertimozilla · firefox · CWE-16 | Yüksek7,5 | — | %78,7 | 27 Tem 2006 |
- CVE-2023-486395Hemen
Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100google · chrome12 Eyl 2023
- CVE-2010-376594Hemen
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, and SeaMonkey 2.x bef
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %83mozilla · firefox27 Eki 2010
- CVE-2019-1170887Hemen
Insufficient vetting of parameters passed with the Prompt:Open IPC message between child and parent processes can result in the non-sandboxe
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %56mozilla · firefox23 Tem 2019
- CVE-2016-907986Hemen
A use-after-free vulnerability in SVG Animation has been discovered.
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %87debian · debian linux11 Haz 2018
- CVE-2013-169086Hemen
Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not proper
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69mozilla · firefox25 Haz 2013
- CVE-2015-449586Hemen
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %69mozilla · firefox7 Ağu 2015
- CVE-2023-521780Hemen
Heap buffer overflow in vp8 encoding in libvpx in Google Chrome prior to 117.0.5938.132 and libvpx 1.13.1 allowed a remote attacker to poten
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %49google · chrome28 Eyl 2023
- CVE-2019-1702679Bu hafta
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %46mozilla · firefox2 Mar 2020
- CVE-2019-1170776Bu hafta
A type confusion vulnerability can occur when manipulating JavaScript objects due to issues in Array.pop.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %38mozilla · firefox23 Tem 2019
- CVE-2024-968076Bu hafta
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %23mozilla · firefox9 Eki 2024
- CVE-2022-2648569Bu hafta
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free.
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %14mozilla · firefox22 Ara 2022
- CVE-2022-2648669Bu hafta
An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape.
KritikCVSS 9,6KEVSilahlaştırılmışEPSS %2mozilla · firefox22 Ara 2022
- CVE-2009-355565Bu hafta
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in th
KritikCVSS 9,8Kavram kanıtıEPSS %87apache · http server9 Kas 2009
- CVE-2014-151164Bu hafta
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remote attackers to bypa
KritikCVSS 9,8SilahlaştırılmışEPSS %84mozilla · firefox19 Mar 2014
- CVE-2014-151064Bu hafta
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25
KritikCVSS 9,8SilahlaştırılmışEPSS %82mozilla · firefox19 Mar 2014
- CVE-2020-682064Bu hafta
Under certain conditions, when handling a ReadableStream, a race condition can cause a use-after-free.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %7mozilla · firefox24 Nis 2020
- CVE-2011-237163Bu hafta
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaM
KritikCVSS 10,0SilahlaştırılmışEPSS %76mozilla · seamonkey30 Haz 2011
- CVE-2020-681963Bu hafta
Under certain conditions, when running the nsDocShell destructor, a race condition can cause a use-after-free.
YüksekCVSS 8,1KEVSilahlaştırılmışEPSS %3mozilla · firefox24 Nis 2020
- CVE-2011-006562Bu hafta
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allows remote attackers
KritikCVSS 10,0SilahlaştırılmışEPSS %74mozilla · firefox7 May 2011
- CVE-2011-007361Bu hafta
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange data structures, which
KritikCVSS 10,0SilahlaştırılmışEPSS %70mozilla · firefox7 May 2011
- CVE-2013-075859Planlayın
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderbird ESR 10.x before
KritikCVSS 9,3SilahlaştırılmışEPSS %73mozilla · firefox13 Oca 2013
- CVE-2013-167558Planlayın
Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbird before 17.0.6, and Thunderbird ESR 17.x before 17.0.6 do not proper
OrtaCVSS 6,5KEVSilahlaştırılmışEPSS %7mozilla · firefox16 May 2013
- CVE-2024-436756Planlayın
A type check was missing when handling fonts in PDF.js, which would allow arbitrary JavaScript execution in the PDF.js context.
YüksekCVSS 8,8Kavram kanıtıEPSS %71mozilla · firefox14 May 2024
- CVE-2013-075755Planlayın
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbird before 17.0.2, Th
KritikCVSS 9,3SilahlaştırılmışEPSS %61mozilla · firefox13 Oca 2013
- CVE-2006-367754Planlayın
Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properti
YüksekCVSS 7,5SilahlaştırılmışEPSS %79mozilla · firefox27 Tem 2006