Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 379
CVE-2017-5393
The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51.
CVE-2017-5393
The "mozAddonManager" allows for the installation of extensions from t ...
CVE-2017-5392
Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51.
CVE-2017-5392
Weak proxy objects have weak references on multiple threads when they ...
CVE-2017-5391
Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51.
CVE-2017-5391
Special "about:" pages used by web content, such as RSS feeds, can loa ...
CVE-2017-5390
The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5390
The JSON viewer in the Developer Tools uses insecure methods to create ...
CVE-2017-5389
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.
CVE-2017-5389
WebExtensions could use the "mozAddonManager" API by modifying the CSP ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5393 The "mozAddonManager" allows for the installation of extensions from the CDN for addons.mozilla.org, a publicly accessible site. This could allow malicious extensions to install additional extensions from the CDN in combination with an XSS attack on Mozilla AMO sites. This vulnerability affects Firefox < 51. | CVSS3: 6.1 | 1% Низкий | около 8 лет назад | |
CVE-2017-5393 The "mozAddonManager" allows for the installation of extensions from t ... | CVSS3: 6.1 | 1% Низкий | около 8 лет назад | |
CVE-2017-5392 Weak proxy objects have weak references on multiple threads when they should only have them on one, resulting in incorrect memory usage and corruption, which leads to potentially exploitable crashes. Note: This issue only affects Firefox for Android. Other operating systems are not affected. This vulnerability affects Firefox < 51. | CVSS3: 9.8 | 2% Низкий | около 8 лет назад | |
CVE-2017-5392 Weak proxy objects have weak references on multiple threads when they ... | CVSS3: 9.8 | 2% Низкий | около 8 лет назад | |
CVE-2017-5391 Special "about:" pages used by web content, such as RSS feeds, can load privileged "about:" pages in an iframe. If a content-injection bug were found in one of those pages this could allow for potential privilege escalation. This vulnerability affects Firefox < 51. | CVSS3: 9.8 | 2% Низкий | около 8 лет назад | |
CVE-2017-5391 Special "about:" pages used by web content, such as RSS feeds, can loa ... | CVSS3: 9.8 | 2% Низкий | около 8 лет назад | |
CVE-2017-5390 The JSON viewer in the Developer Tools uses insecure methods to create a communication channel for copying and viewing JSON or HTTP headers data, allowing for potential privilege escalation. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. | CVSS3: 9.8 | 4% Низкий | около 8 лет назад | |
CVE-2017-5390 The JSON viewer in the Developer Tools uses insecure methods to create ... | CVSS3: 9.8 | 4% Низкий | около 8 лет назад | |
CVE-2017-5389 WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51. | CVSS3: 6.1 | 1% Низкий | около 8 лет назад | |
CVE-2017-5389 WebExtensions could use the "mozAddonManager" API by modifying the CSP ... | CVSS3: 6.1 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу