Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 368
CVE-2017-5464
During DOM manipulations of the accessibility tree through script, the ...
CVE-2017-5463
Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of the addressbar as displayed to users. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53.
CVE-2017-5463
Android intents can be used to launch Firefox for Android in reader mo ...
CVE-2017-5462
A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5462
A flaw in DRBG number generation within the Network Security Services ...
CVE-2017-5460
A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5460
A use-after-free vulnerability in frame selection triggered by a combi ...
CVE-2017-5459
A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5459
A buffer overflow in WebGL triggerable by web content, resulting in a ...
CVE-2017-5458
When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5464 During DOM manipulations of the accessibility tree through script, the ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-5463 Android intents can be used to launch Firefox for Android in reader mode with a user specified URL. This allows an attacker to spoof the contents of the addressbar as displayed to users. Note: This attack only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 53. | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2017-5463 Android intents can be used to launch Firefox for Android in reader mo ... | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2017-5462 A flaw in DRBG number generation within the Network Security Services (NSS) library where the internal state V does not correctly carry bits over. The NSS library has been updated to fix this issue to address this issue and Firefox ESR 52.1 has been updated with NSS version 3.28.4. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 5.3 | 3% Низкий | около 8 лет назад | |
CVE-2017-5462 A flaw in DRBG number generation within the Network Security Services ... | CVSS3: 5.3 | 3% Низкий | около 8 лет назад | |
CVE-2017-5460 A use-after-free vulnerability in frame selection triggered by a combination of malicious script content and key presses by a user. This results in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-5460 A use-after-free vulnerability in frame selection triggered by a combi ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-5459 A buffer overflow in WebGL triggerable by web content, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 9.8 | 5% Низкий | около 8 лет назад | |
CVE-2017-5459 A buffer overflow in WebGL triggerable by web content, resulting in a ... | CVSS3: 9.8 | 5% Низкий | около 8 лет назад | |
CVE-2017-5458 When a "javascript:" URL is drag and dropped by a user into the addressbar, the URL will be processed and executed. This allows for users to be socially engineered to execute an XSS attack on themselves. This vulnerability affects Firefox < 53. | CVSS3: 6.1 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу