Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 368
CVE-2017-7793
A use-after-free vulnerability can occur in the Fetch API when the wor ...
CVE-2017-7792
A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVE-2017-7792
A buffer overflow will occur when viewing a certificate in the certifi ...
CVE-2017-7791
On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55.
CVE-2017-7791
On pages containing an iframe, the "data:" protocol can be used to cre ...
CVE-2017-7790
On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, stack memory data can be copied until a null is found. This can potentially contain private data from the local system. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Firefox < 55.
CVE-2017-7790
On Windows systems, if non-null-terminated strings are copied into the ...
CVE-2017-7789
If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55.
CVE-2017-7789
If a server sends two Strict-Transport-Security (STS) headers for a si ...
CVE-2017-7788
When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-7793 A use-after-free vulnerability can occur in the Fetch API when the wor ... | CVSS3: 9.8 | 2% Низкий | около 8 лет назад | |
CVE-2017-7792 A buffer overflow will occur when viewing a certificate in the certificate manager if the certificate has an extremely long object identifier (OID). This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-7792 A buffer overflow will occur when viewing a certificate in the certifi ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-7791 On pages containing an iframe, the "data:" protocol can be used to create a modal alert that will render over arbitrary domains following page navigation, spoofing of the origin of the modal alert from the iframe content. This vulnerability affects Thunderbird < 52.3, Firefox ESR < 52.3, and Firefox < 55. | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2017-7791 On pages containing an iframe, the "data:" protocol can be used to cre ... | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2017-7790 On Windows systems, if non-null-terminated strings are copied into the crash reporter for some specific registry keys, stack memory data can be copied until a null is found. This can potentially contain private data from the local system. Note: This attack only affects Windows operating systems. Other operating systems are not affected. This vulnerability affects Firefox < 55. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-7790 On Windows systems, if non-null-terminated strings are copied into the ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-7789 If a server sends two Strict-Transport-Security (STS) headers for a single connection, they will be rejected as invalid and HTTP Strict Transport Security (HSTS) will not be enabled for the connection. This vulnerability affects Firefox < 55. | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2017-7789 If a server sends two Strict-Transport-Security (STS) headers for a si ... | CVSS3: 5.3 | 2% Низкий | около 8 лет назад | |
CVE-2017-7788 When an "iframe" has a "sandbox" attribute and its content is specified using "srcdoc", that content does not inherit the containing page's Content Security Policy (CSP) as it should unless the sandbox attribute included "allow-same-origin". This vulnerability affects Firefox < 55. | CVSS3: 9.8 | 2% Низкий | около 8 лет назад |
Уязвимостей на страницу