Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2018-5166
WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60.
CVE-2018-5166
WebExtensions can use request redirection and a "filterReponseData" fi ...
CVE-2018-5165
In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn protections off. This vulnerability affects Firefox < 60.
CVE-2018-5165
In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Ena ...
CVE-2018-5164
Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60.
CVE-2018-5164
Content Security Policy (CSP) is not applied correctly to all parts of ...
CVE-2018-5163
If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60.
CVE-2018-5163
If a malicious attacker has used another vulnerability to gain full co ...
CVE-2018-5160
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60.
CVE-2018-5160
WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-5166 WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have explicit user permission. This vulnerability affects Firefox < 60. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5166 WebExtensions can use request redirection and a "filterReponseData" fi ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5165 In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Enable Adobe Flash protected mode" is unchecked by default even though the Adobe Flash sandbox is actually enabled. The displayed state is the reverse of the true setting, resulting in user confusion. This could cause users to select this setting intending to activate it and inadvertently turn protections off. This vulnerability affects Firefox < 60. | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2018-5165 In 32-bit versions of Firefox, the Adobe Flash plugin setting for "Ena ... | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2018-5164 Content Security Policy (CSP) is not applied correctly to all parts of multipart content sent with the "multipart/x-mixed-replace" MIME type. This could allow for script to run where CSP should block it, allowing for cross-site scripting (XSS) and other attacks. This vulnerability affects Firefox < 60. | CVSS3: 6.1 | 2% Низкий | около 8 лет назад | |
CVE-2018-5164 Content Security Policy (CSP) is not applied correctly to all parts of ... | CVSS3: 6.1 | 2% Низкий | около 8 лет назад | |
CVE-2018-5163 If a malicious attacker has used another vulnerability to gain full control over a content process, they may be able to replace the alternate data resources stored in the JavaScript Start-up Bytecode Cache (JSBC) for other JavaScript code. If the parent process then runs this replaced code, the executed script would be run with the parent process' privileges, escaping the sandbox on content processes. This vulnerability affects Firefox < 60. | CVSS3: 8.1 | 2% Низкий | около 8 лет назад | |
CVE-2018-5163 If a malicious attacker has used another vulnerability to gain full co ... | CVSS3: 8.1 | 2% Низкий | около 8 лет назад | |
CVE-2018-5160 WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a potentially exploitable crash. This vulnerability affects Firefox < 60. | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2018-5160 WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image ... | CVSS3: 7.5 | 3% Низкий | около 8 лет назад |
Уязвимостей на страницу