Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 368
CVE-2017-5452
Malicious sites can display a spoofed addressbar on a page when the ex ...
CVE-2017-5451
A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5451
A mechanism to spoof the addressbar through the user interaction on th ...
CVE-2017-5450
A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, making the resulting location less visibly a spoofed site and showing an incorrect domain in appended notifications. This vulnerability affects Firefox < 53.
CVE-2017-5450
A mechanism to spoof the Firefox for Android addressbar using a "javas ...
CVE-2017-5449
A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5449
A possibly exploitable crash triggered during layout and manipulation ...
CVE-2017-5448
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
CVE-2017-5448
An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Cl ...
CVE-2017-5447
An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5452 Malicious sites can display a spoofed addressbar on a page when the ex ... | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
CVE-2017-5451 A mechanism to spoof the addressbar through the user interaction on the addressbar and the "onblur" event. The event could be used by script to affect text display to make the loaded site appear to be different from the one actually loaded within the addressbar. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 4.3 | 2% Низкий | около 8 лет назад | |
CVE-2017-5451 A mechanism to spoof the addressbar through the user interaction on th ... | CVSS3: 4.3 | 2% Низкий | около 8 лет назад | |
CVE-2017-5450 A mechanism to spoof the Firefox for Android addressbar using a "javascript:" URI. On Firefox for Android, the base domain is parsed incorrectly, making the resulting location less visibly a spoofed site and showing an incorrect domain in appended notifications. This vulnerability affects Firefox < 53. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-5450 A mechanism to spoof the Firefox for Android addressbar using a "javas ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-5449 A possibly exploitable crash triggered during layout and manipulation of bidirectional unicode text in concert with CSS animations. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2017-5449 A possibly exploitable crash triggered during layout and manipulation ... | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2017-5448 An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Clearkey-encrypted media content. The "ClearKeyDecryptor" code runs within the Gecko Media Plugin (GMP) sandbox. If a second mechanism is found to escape the sandbox, this vulnerability allows for the writing of arbitrary data within memory, resulting in a potentially exploitable crash. This vulnerability affects Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 8.6 | 2% Низкий | около 8 лет назад | |
CVE-2017-5448 An out-of-bounds write in "ClearKeyDecryptor" while decrypting some Cl ... | CVSS3: 8.6 | 2% Низкий | около 8 лет назад | |
CVE-2017-5447 An out-of-bounds read during the processing of glyph widths during text layout. This results in a potentially exploitable crash and could allow an attacker to read otherwise inaccessible memory. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 45.9, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 9.1 | 17% Средний | около 8 лет назад |
Уязвимостей на страницу