Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 379
CVE-2016-9068
A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50.
CVE-2016-9068
A use-after-free during web animations when working with timelines res ...
CVE-2016-9067
Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50.
CVE-2016-9067
Two use-after-free errors during DOM operations resulting in potential ...
CVE-2016-9066
A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50.
CVE-2016-9066
A buffer overflow resulting in a potentially exploitable crash due to ...
CVE-2016-9065
The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50.
CVE-2016-9065
The location bar in Firefox for Android can be spoofed by forcing a us ...
CVE-2016-9064
Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50.
CVE-2016-9064
Add-on updates failed to verify that the add-on ID inside the signed p ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-9068 A use-after-free during web animations when working with timelines resulting in a potentially exploitable crash. This vulnerability affects Firefox < 50. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2016-9068 A use-after-free during web animations when working with timelines res ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2016-9067 Two use-after-free errors during DOM operations resulting in potentially exploitable crashes. This vulnerability affects Firefox < 50. | CVSS3: 6.5 | 2% Низкий | около 8 лет назад | |
CVE-2016-9067 Two use-after-free errors during DOM operations resulting in potential ... | CVSS3: 6.5 | 2% Низкий | около 8 лет назад | |
CVE-2016-9066 A buffer overflow resulting in a potentially exploitable crash due to memory allocation issues when handling large amounts of incoming data. This vulnerability affects Thunderbird < 45.5, Firefox ESR < 45.5, and Firefox < 50. | CVSS3: 7.5 | 12% Средний | около 8 лет назад | |
CVE-2016-9066 A buffer overflow resulting in a potentially exploitable crash due to ... | CVSS3: 7.5 | 12% Средний | около 8 лет назад | |
CVE-2016-9065 The location bar in Firefox for Android can be spoofed by forcing a user into fullscreen mode, blocking its exiting, and creating of a fake location bar without any user notification. Note: This issue only affects Firefox for Android. Other versions and operating systems are unaffected. This vulnerability affects Firefox < 50. | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2016-9065 The location bar in Firefox for Android can be spoofed by forcing a us ... | CVSS3: 7.5 | 2% Низкий | около 8 лет назад | |
CVE-2016-9064 Add-on updates failed to verify that the add-on ID inside the signed package matched the ID of the add-on being updated. An attacker who could perform a man-in-the-middle attack on the user's connection to the update server and defeat the certificate pinning protection could provide a malicious signed add-on instead of a valid update. This vulnerability affects Firefox ESR < 45.5 and Firefox < 50. | CVSS3: 5.9 | 1% Низкий | около 8 лет назад | |
CVE-2016-9064 Add-on updates failed to verify that the add-on ID inside the signed p ... | CVSS3: 5.9 | 1% Низкий | около 8 лет назад |
Уязвимостей на страницу