Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 368
CVE-2017-7809
A use-after-free vulnerability can occur when an editor DOM node is de ...
CVE-2017-7808
A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55.
CVE-2017-7808
A content security policy (CSP) "frame-ancestors" directive containing ...
CVE-2017-7807
A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVE-2017-7807
A mechanism that uses AppCache to hijack a URL in a domain using fallb ...
CVE-2017-7806
A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55.
CVE-2017-7806
A use-after-free vulnerability can occur when the layer manager is fre ...
CVE-2017-7805
During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4.
CVE-2017-7805
During TLS 1.2 exchanges, handshake hashes are generated which point t ...
CVE-2017-7804
The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memory protections in this situation. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-7809 A use-after-free vulnerability can occur when an editor DOM node is de ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-7808 A content security policy (CSP) "frame-ancestors" directive containing origins with paths allows for comparisons against those paths instead of the origin. This results in a cross-origin information leak of this path information. This vulnerability affects Firefox < 55. | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2017-7808 A content security policy (CSP) "frame-ancestors" directive containing ... | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2017-7807 A mechanism that uses AppCache to hijack a URL in a domain using fallback by serving the files from a sub-path on the domain. This has been addressed by requiring fallback files be inside the manifest directory. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | CVSS3: 8.1 | 2% Низкий | около 8 лет назад | |
CVE-2017-7807 A mechanism that uses AppCache to hijack a URL in a domain using fallb ... | CVSS3: 8.1 | 2% Низкий | около 8 лет назад | |
CVE-2017-7806 A use-after-free vulnerability can occur when the layer manager is freed too early when rendering specific SVG content, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 55. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-7806 A use-after-free vulnerability can occur when the layer manager is fre ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-7805 During TLS 1.2 exchanges, handshake hashes are generated which point to a message buffer. This saved data is used for later messages but in some cases, the handshake transcript can exceed the space available in the current buffer, causing the allocation of a new buffer. This leaves a pointer pointing to the old, freed buffer, resulting in a use-after-free when handshake hashes are then calculated afterwards. This can result in a potentially exploitable crash. This vulnerability affects Firefox < 56, Firefox ESR < 52.4, and Thunderbird < 52.4. | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2017-7805 During TLS 1.2 exchanges, handshake hashes are generated which point t ... | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2017-7804 The destructor function for the "WindowsDllDetourPatcher" class can be re-purposed by malicious code in concert with another vulnerability to write arbitrary data to an attacker controlled location in memory. This can be used to bypass existing memory protections in this situation. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | CVSS3: 7.5 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу