Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 427
CVE-2018-5108
A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58.
CVE-2018-5108
A Blob URL can violate origin attribute segregation, allowing it to be ...
CVE-2018-5107
The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing process requires files in a specific format so arbitrary data cannot be read but it is possible that some local file information could be exposed. This vulnerability affects Firefox < 58.
CVE-2018-5107
The printing process can bypass local access protections to read files ...
CVE-2018-5106
Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open. This can allow style editor information used within Developer Tools to leak cross-origin. This vulnerability affects Firefox < 58.
CVE-2018-5106
Style editor traffic in the Developer Tools can be routed through a se ...
CVE-2018-5105
WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58.
CVE-2018-5105
WebExtensions can bypass user prompts to first save and then open an a ...
CVE-2018-5104
A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58.
CVE-2018-5104
A use-after-free vulnerability can occur during font face manipulation ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-5108 A Blob URL can violate origin attribute segregation, allowing it to be accessed from a private browsing tab and for data to be passed between the private browsing tab and a normal tab. This could allow for the leaking of private information specific to the private browsing context. This issue is mitigated by the requirement that the user enter the Blob URL manually in order for the access violation to occur. This vulnerability affects Firefox < 58. | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-5108 A Blob URL can violate origin attribute segregation, allowing it to be ... | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-5107 The printing process can bypass local access protections to read files available through symlinks, bypassing local file restrictions. The printing process requires files in a specific format so arbitrary data cannot be read but it is possible that some local file information could be exposed. This vulnerability affects Firefox < 58. | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2018-5107 The printing process can bypass local access protections to read files ... | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2018-5106 Style editor traffic in the Developer Tools can be routed through a service worker hosted on a third party website if a user selects error links when these tools are open. This can allow style editor information used within Developer Tools to leak cross-origin. This vulnerability affects Firefox < 58. | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-5106 Style editor traffic in the Developer Tools can be routed through a se ... | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-5105 WebExtensions can bypass user prompts to first save and then open an arbitrarily downloaded file. This can result in an executable file running with local user privileges without explicit user consent. This vulnerability affects Firefox < 58. | CVSS3: 7.8 | 0% Низкий | около 8 лет назад | |
CVE-2018-5105 WebExtensions can bypass user prompts to first save and then open an a ... | CVSS3: 7.8 | 0% Низкий | около 8 лет назад | |
CVE-2018-5104 A use-after-free vulnerability can occur during font face manipulation when a font face is freed while still in use, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.6, Firefox ESR < 52.6, and Firefox < 58. | CVSS3: 9.8 | 7% Низкий | около 8 лет назад | |
CVE-2018-5104 A use-after-free vulnerability can occur during font face manipulation ... | CVSS3: 9.8 | 7% Низкий | около 8 лет назад |
Уязвимостей на страницу