Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 379
CVE-2017-5373
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51.
CVE-2017-5373
Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. ...
CVE-2016-9905
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
CVE-2016-9905
A potentially exploitable crash in "EnumerateSubDocuments" while addin ...
CVE-2016-9904
An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6.
CVE-2016-9904
An attacker could use a JavaScript Map/Set timing attack to determine ...
CVE-2016-9903
Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1.
CVE-2016-9903
Mozilla's add-ons SDK had a world-accessible resource with an HTML inj ...
CVE-2016-9902
The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1.
CVE-2016-9902
The Pocket toolbar button, once activated, listens for events fired fr ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2017-5373 Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 45.7, Firefox ESR < 45.7, and Firefox < 51. | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2017-5373 Memory safety bugs were reported in Firefox 50.1 and Firefox ESR 45.6. ... | CVSS3: 9.8 | 3% Низкий | около 8 лет назад | |
CVE-2016-9905 A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6. | CVSS3: 8.8 | 2% Низкий | около 8 лет назад | |
CVE-2016-9905 A potentially exploitable crash in "EnumerateSubDocuments" while addin ... | CVSS3: 8.8 | 2% Низкий | около 8 лет назад | |
CVE-2016-9904 An attacker could use a JavaScript Map/Set timing attack to determine whether an atom is used by another compartment/zone in specific contexts. This could be used to leak information, such as usernames embedded in JavaScript code, across websites. This vulnerability affects Firefox < 50.1, Firefox ESR < 45.6, and Thunderbird < 45.6. | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2016-9904 An attacker could use a JavaScript Map/Set timing attack to determine ... | CVSS3: 7.5 | 3% Низкий | около 8 лет назад | |
CVE-2016-9903 Mozilla's add-ons SDK had a world-accessible resource with an HTML injection vulnerability. If an additional vulnerability allowed this resource to be loaded as a document it could allow injecting content and script into an add-on's context. This vulnerability affects Firefox < 50.1. | CVSS3: 6.1 | 1% Низкий | около 8 лет назад | |
CVE-2016-9903 Mozilla's add-ons SDK had a world-accessible resource with an HTML inj ... | CVSS3: 6.1 | 1% Низкий | около 8 лет назад | |
CVE-2016-9902 The Pocket toolbar button, once activated, listens for events fired from it's own pages but does not verify the origin of incoming events. This allows content from other origins to fire events and inject content and commands into the Pocket context. Note: this issue does not affect users with e10s enabled. This vulnerability affects Firefox ESR < 45.6 and Firefox < 50.1. | CVSS3: 7.5 | 1% Низкий | около 8 лет назад | |
CVE-2016-9902 The Pocket toolbar button, once activated, listens for events fired fr ... | CVSS3: 7.5 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу