Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 368
CVE-2017-5398
Memory safety bugs were reported in Thunderbird 45.7. Some of these bu ...
CVE-2017-5397
The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3.
CVE-2017-5397
The cache directory on the local file system is set to be world writab ...
CVE-2017-5396
A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5396
A use-after-free vulnerability in the Media Decoder when working with ...
CVE-2017-5395
Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
CVE-2017-5395
Malicious sites can display a spoofed location bar on a subsequently l ...
CVE-2017-5394
A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
CVE-2017-5394
A location bar spoofing attack where the location bar of loaded page w ...
CVE-2017-5393
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5398 Memory safety bugs were reported in Thunderbird 45.7. Some of these bu ... | CVSS3: 9.8 | 4% Низкий | около 8 лет назад | |
CVE-2017-5397 The cache directory on the local file system is set to be world writable. Firefox defaults to extracting libraries from this cache. This allows for the possibility of an installed malicious application or tools with write access to the file system to replace files used by Firefox with their own versions. This vulnerability affects Firefox < 51.0.3. | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-5397 The cache directory on the local file system is set to be world writab ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-5396 A use-after-free vulnerability in the Media Decoder when working with media files when some events are fired after the media elements are freed from memory. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. | CVSS3: 9.8 | 4% Низкий | около 8 лет назад | |
CVE-2017-5396 A use-after-free vulnerability in the Media Decoder when working with ... | CVSS3: 9.8 | 4% Низкий | около 8 лет назад | |
CVE-2017-5395 Malicious sites can display a spoofed location bar on a subsequently loaded page when the existing location bar on the new page is scrolled out of view if navigations between pages can be timed correctly. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51. | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
CVE-2017-5395 Malicious sites can display a spoofed location bar on a subsequently l ... | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
CVE-2017-5394 A location bar spoofing attack where the location bar of loaded page will be shown over the content of another tab due to a series of JavaScript events combined with fullscreen mode. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51. | CVSS3: 8.8 | 1% Низкий | около 8 лет назад | |
CVE-2017-5394 A location bar spoofing attack where the location bar of loaded page w ... | CVSS3: 8.8 | 1% Низкий | около 8 лет назад | |
CVE-2017-5393 The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51. | CVSS3: 6.1 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу