Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2018-5113
The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58.
CVE-2018-5113
The "browser.identity.launchWebAuthFlow" function of WebExtensions is ...
CVE-2018-5112
Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58.
CVE-2018-5112
Development Tools panels of an extension are required to load URLs for ...
CVE-2018-5111
When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58.
CVE-2018-5111
When the text of a specially formatted URL is dragged to the addressba ...
CVE-2018-5110
If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible within Firefox. Note: This vulnerability only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 58.
CVE-2018-5110
If cursor visibility is toggled by script using from 'none' to an imag ...
CVE-2018-5109
An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58.
CVE-2018-5109
An audio capture session can started under an incorrect origin from th ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-5113 The "browser.identity.launchWebAuthFlow" function of WebExtensions is only allowed to load content over "https:" but this requirement was not properly enforced. This can potentially allow privileged pages to be loaded by the extension. This vulnerability affects Firefox < 58. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5113 The "browser.identity.launchWebAuthFlow" function of WebExtensions is ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5112 Development Tools panels of an extension are required to load URLs for the panels as relative URLs from the extension manifest file but this requirement was not enforced in all instances. This could allow the development tools panel for the extension to load a URL that it should not be able to access, including potentially privileged pages. This vulnerability affects Firefox < 58. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5112 Development Tools panels of an extension are required to load URLs for ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5111 When the text of a specially formatted URL is dragged to the addressbar from page content, the displayed URL can be spoofed to show a different site than the one loaded. This allows for phishing attacks where a malicious page can spoof the identify of another site. This vulnerability affects Firefox < 58. | CVSS3: 6.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5111 When the text of a specially formatted URL is dragged to the addressba ... | CVSS3: 6.5 | 2% Низкий | около 8 лет назад | |
CVE-2018-5110 If cursor visibility is toggled by script using from 'none' to an image and back through script, the cursor will be rendered temporarily invisible within Firefox. Note: This vulnerability only affects OS X. Other operating systems are not affected. This vulnerability affects Firefox < 58. | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-5110 If cursor visibility is toggled by script using from 'none' to an imag ... | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-5109 An audio capture session can started under an incorrect origin from the site making the capture request. Users are still prompted to allow the request but the prompt can display the wrong origin, leading to user confusion about which site is making the request to capture an audio stream. This vulnerability affects Firefox < 58. | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-5109 An audio capture session can started under an incorrect origin from th ... | CVSS3: 5.3 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу