Pale Moon
Vendor:
First CVE: Jan 31, 2013 · Active for 13 years
3
Total CVEs
More Total CVEs than 68% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
9.0
Avg CVSS
Higher Avg CVSS than 84% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pale Moon over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 31, 2013
13 years ago
Most Recent CVE
Mar 2, 2020
2,339 days ago
CVE Severity & Scoring
Pale Moon3 CVEs
33%
67%
All CVEs353,173 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network3 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None3 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None3 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12292CRITICAL A use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3. | Jun 13, 2018 | 9.8 | 43 | NO | YES |
CVE-2013-1591CRITICAL Stack-based buffer overflow in libpixman, as used in Pale Moon before 15.4 and possibly other products, has unspecified impact and context-dependent attack vectors. NOTE: this iss | Jan 31, 2013 | 9.8 | 25 | NO | NO |
CVE-2020-9545HIGH Pale Moon 28.x before 28.8.4 has a segmentation fault related to module scripting, as demonstrated by a Lacoste web site. | Mar 2, 2020 | 7.5 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (3 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
33.3% of CVEs· 88th percentile
Social Chatter
Signals from CVEs in this product scope (3 CVEs).
Media Mentions
Signals from CVEs in this product scope (3 CVEs).
Top CNAs Publishing CVEs For Pale Moon
Top CWEs
Versions
No cataloged versions.