Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 368
CVE-2017-5408
Video files loaded video captions cross-origin without checking for th ...
CVE-2017-5407
Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
CVE-2017-5407
Using SVG filters that don't use the fixed point math implementation o ...
CVE-2017-5406
A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52.
CVE-2017-5406
A segmentation fault can occur in the Skia graphics library during som ...
CVE-2017-5405
Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
CVE-2017-5405
Certain response codes in FTP connections can result in the use of uni ...
CVE-2017-5404
A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8.
CVE-2017-5404
A use-after-free error can occur when manipulating ranges in selection ...
CVE-2017-5403
When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thunderbird < 52.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5408 Video files loaded video captions cross-origin without checking for th ... | CVSS3: 5.3 | 3% Низкий | около 8 лет назад | |
CVE-2017-5407 Using SVG filters that don't use the fixed point math implementation on a target iframe, a malicious page can extract pixel values from a targeted user. This can be used to extract history information and read text values across domains. This violates same-origin policy and leads to information disclosure. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. | CVSS3: 6.5 | 3% Низкий | около 8 лет назад | |
CVE-2017-5407 Using SVG filters that don't use the fixed point math implementation o ... | CVSS3: 6.5 | 3% Низкий | около 8 лет назад | |
CVE-2017-5406 A segmentation fault can occur in the Skia graphics library during some canvas operations due to issues with mask/clip intersection and empty masks. This vulnerability affects Firefox < 52 and Thunderbird < 52. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-5406 A segmentation fault can occur in the Skia graphics library during som ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2017-5405 Certain response codes in FTP connections can result in the use of uninitialized values for ports in FTP operations. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. | CVSS3: 5.3 | 3% Низкий | около 8 лет назад | |
CVE-2017-5405 Certain response codes in FTP connections can result in the use of uni ... | CVSS3: 5.3 | 3% Низкий | около 8 лет назад | |
CVE-2017-5404 A use-after-free error can occur when manipulating ranges in selections with one node inside a native anonymous tree and one node outside of it. This results in a potentially exploitable crash. This vulnerability affects Firefox < 52, Firefox ESR < 45.8, Thunderbird < 52, and Thunderbird < 45.8. | CVSS3: 9.8 | 17% Средний | около 8 лет назад | |
CVE-2017-5404 A use-after-free error can occur when manipulating ranges in selection ... | CVSS3: 9.8 | 17% Средний | около 8 лет назад | |
CVE-2017-5403 When adding a range to an object in the DOM, it is possible to use "addRange" to add the range to an incorrect root object. This triggers a use-after-free, resulting in a potentially exploitable crash. This vulnerability affects Firefox < 52 and Thunderbird < 52. | CVSS3: 9.8 | 2% Низкий | около 8 лет назад |
Уязвимостей на страницу