Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 368
CVE-2017-5469
Fixed potential buffer overflows in generated Firefox code due to CVE- ...
CVE-2017-5468
An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53.
CVE-2017-5468
An issue with incorrect ownership model of "privateBrowsing" informati ...
CVE-2017-5467
A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5467
A potential memory corruption and crash when using Skia content when d ...
CVE-2017-5466
If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5466
If a page is loaded from an original site through a hyperlink and cont ...
CVE-2017-5465
An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5465
An out-of-bounds read while processing SVG content in "ConvolvePixel". ...
CVE-2017-5464
During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5469 Fixed potential buffer overflows in generated Firefox code due to CVE- ... | CVSS3: 9.8 | 5% Низкий | около 8 лет назад | |
CVE-2017-5468 An issue with incorrect ownership model of "privateBrowsing" information exposed through developer tools. This can result in a non-exploitable crash when manually triggered during debugging. This vulnerability affects Firefox < 53. | CVSS3: 9.1 | 2% Низкий | около 8 лет назад | |
CVE-2017-5468 An issue with incorrect ownership model of "privateBrowsing" informati ... | CVSS3: 9.1 | 2% Низкий | около 8 лет назад | |
CVE-2017-5467 A potential memory corruption and crash when using Skia content when drawing content outside of the bounds of a clipping region. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-5467 A potential memory corruption and crash when using Skia content when d ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-5466 If a page is loaded from an original site through a hyperlink and contains a redirect to a "data:text/html" URL, triggering a reload will run the reloaded "data:text/html" page with its origin set incorrectly. This allows for a cross-site scripting (XSS) attack. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 6.1 | 2% Низкий | около 8 лет назад | |
CVE-2017-5466 If a page is loaded from an original site through a hyperlink and cont ... | CVSS3: 6.1 | 2% Низкий | около 8 лет назад | |
CVE-2017-5465 An out-of-bounds read while processing SVG content in "ConvolvePixel". This results in a crash and also allows for otherwise inaccessible memory being copied into SVG graphic content, which could then displayed. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 9.1 | 19% Средний | около 8 лет назад | |
CVE-2017-5465 An out-of-bounds read while processing SVG content in "ConvolvePixel". ... | CVSS3: 9.1 | 19% Средний | около 8 лет назад | |
CVE-2017-5464 During DOM manipulations of the accessibility tree through script, the DOM tree can become out of sync with the accessibility tree, leading to memory corruption and a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 9.8 | 3% Низкий | около 8 лет назад |
Уязвимостей на страницу