Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Количество 15 501
GHSA-phcc-6pmp-qw9v
Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19.
CVE-2025-0247
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134 and Thunderbird < 134.
CVE-2025-0247
Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of ...
CVE-2025-0246
When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134.
CVE-2025-0246
When using an invalid protocol scheme, an attacker could spoof the add ...
CVE-2025-0245
Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134.
CVE-2025-0245
Under certain circumstances, a user opt-in setting that Focus should r ...
CVE-2025-0244
When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 134.
CVE-2025-0244
When redirecting to an invalid protocol scheme, an attacker could spoo ...
CVE-2025-0243
Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
GHSA-phcc-6pmp-qw9v Assuming a controlled failed memory allocation, an attacker could have caused a use-after-free, leading to a potentially exploitable crash. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, and Firefox ESR < 115.19. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
CVE-2025-0247 Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134 and Thunderbird < 134. | CVSS3: 9.8 | 1% Низкий | около 1 года назад | |
CVE-2025-0247 Memory safety bugs present in Firefox 133 and Thunderbird 133. Some of ... | CVSS3: 9.8 | 1% Низкий | около 1 года назад | |
CVE-2025-0246 When using an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* *Note: This issue is a different issue from CVE-2025-0244. This vulnerability affects Firefox < 134. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
CVE-2025-0246 When using an invalid protocol scheme, an attacker could spoof the add ... | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
CVE-2025-0245 Under certain circumstances, a user opt-in setting that Focus should require authentication before use could have been be bypassed. This vulnerability affects Firefox < 134. | CVSS3: 3.3 | 0% Низкий | около 1 года назад | |
CVE-2025-0245 Under certain circumstances, a user opt-in setting that Focus should r ... | CVSS3: 3.3 | 0% Низкий | около 1 года назад | |
CVE-2025-0244 When redirecting to an invalid protocol scheme, an attacker could spoof the address bar. *Note: This issue only affected Android operating systems. Other operating systems are unaffected.* This vulnerability affects Firefox < 134. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
CVE-2025-0244 When redirecting to an invalid protocol scheme, an attacker could spoo ... | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
CVE-2025-0243 Memory safety bugs present in Firefox 133, Thunderbird 133, Firefox ESR 128.5, and Thunderbird 128.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 134, Firefox ESR < 128.6, Thunderbird < 134, and Thunderbird < 128.6. | CVSS3: 5.1 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу