Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2018-5147
The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1.
CVE-2018-5147
The libtremor library has the same flaw as CVE-2018-5146. This library ...
CVE-2018-5146
An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7.
CVE-2018-5146
An out of bounds memory write while processing Vorbis audio data was r ...
CVE-2018-5145
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
CVE-2018-5145
Memory safety bugs were reported in Firefox ESR 52.6. These bugs showe ...
CVE-2018-5144
An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7.
CVE-2018-5144
An integer overflow can occur during conversion of text to some Unicod ...
CVE-2018-5143
URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Firefox < 59.
CVE-2018-5143
URLs using "javascript:" have the protocol removed when pasted into th ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-5147 The libtremor library has the same flaw as CVE-2018-5146. This library is used by Firefox in place of libvorbis on Android and ARM platforms. This vulnerability affects Firefox ESR < 52.7.2 and Firefox < 59.0.1. | CVSS3: 9.8 | 2% Низкий | около 8 лет назад | |
CVE-2018-5147 The libtremor library has the same flaw as CVE-2018-5146. This library ... | CVSS3: 9.8 | 2% Низкий | около 8 лет назад | |
CVE-2018-5146 An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7. | CVSS3: 8.8 | 12% Средний | около 8 лет назад | |
CVE-2018-5146 An out of bounds memory write while processing Vorbis audio data was r ... | CVSS3: 8.8 | 12% Средний | около 8 лет назад | |
CVE-2018-5145 Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7. | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2018-5145 Memory safety bugs were reported in Firefox ESR 52.6. These bugs showe ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2018-5144 An integer overflow can occur during conversion of text to some Unicode character sets due to an unchecked length parameter. This vulnerability affects Firefox ESR < 52.7 and Thunderbird < 52.7. | CVSS3: 7.3 | 3% Низкий | около 8 лет назад | |
CVE-2018-5144 An integer overflow can occur during conversion of text to some Unicod ... | CVSS3: 7.3 | 3% Низкий | около 8 лет назад | |
CVE-2018-5143 URLs using "javascript:" have the protocol removed when pasted into the addressbar to protect users from cross-site scripting (XSS) attacks, but if a tab character is embedded in the "javascript:" URL the protocol is not removed and the script will execute. This could allow users to be socially engineered to run an XSS attack against themselves. This vulnerability affects Firefox < 59. | CVSS3: 6.1 | 1% Низкий | около 8 лет назад | |
CVE-2018-5143 URLs using "javascript:" have the protocol removed when pasted into th ... | CVSS3: 6.1 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу