Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-5282
Mozilla Firefox before 49.0 does not properly restrict the scheme in f ...
CVE-2016-5282
Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource.
CVE-2016-5281
Use-after-free vulnerability in the DOMSVGLength class in Mozilla Fire ...
CVE-2016-5281
Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document.
CVE-2016-5280
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityM ...
CVE-2016-5280
Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text.
CVE-2016-5279
Mozilla Firefox before 49.0 allows user-assisted remote attackers to o ...
CVE-2016-5279
Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code.
CVE-2016-5278
Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function ...
CVE-2016-5278
Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-5282 Mozilla Firefox before 49.0 does not properly restrict the scheme in f ... | CVSS3: 6.5 | 2% Низкий | почти 10 лет назад | |
CVE-2016-5282 Mozilla Firefox before 49.0 does not properly restrict the scheme in favicon requests, which might allow remote attackers to obtain sensitive information via unspecified vectors, as demonstrated by a jar: URL for a favicon resource. | CVSS3: 6.5 | 2% Низкий | почти 10 лет назад | |
CVE-2016-5281 Use-after-free vulnerability in the DOMSVGLength class in Mozilla Fire ... | CVSS3: 9.8 | 5% Низкий | почти 10 лет назад | |
CVE-2016-5281 Use-after-free vulnerability in the DOMSVGLength class in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code by leveraging improper interaction between JavaScript code and an SVG document. | CVSS3: 9.8 | 5% Низкий | почти 10 лет назад | |
CVE-2016-5280 Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityM ... | CVSS3: 9.8 | 5% Низкий | почти 10 лет назад | |
CVE-2016-5280 Use-after-free vulnerability in the mozilla::nsTextNodeDirectionalityMap::RemoveElementFromMap function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via bidirectional text. | CVSS3: 9.8 | 5% Низкий | почти 10 лет назад | |
CVE-2016-5279 Mozilla Firefox before 49.0 allows user-assisted remote attackers to o ... | CVSS3: 4.3 | 1% Низкий | почти 10 лет назад | |
CVE-2016-5279 Mozilla Firefox before 49.0 allows user-assisted remote attackers to obtain sensitive full-pathname information during a local-file drag-and-drop operation via crafted JavaScript code. | CVSS3: 4.3 | 1% Низкий | почти 10 лет назад | |
CVE-2016-5278 Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function ... | CVSS3: 8.8 | 4% Низкий | почти 10 лет назад | |
CVE-2016-5278 Heap-based buffer overflow in the nsBMPEncoder::AddImageFrame function in Mozilla Firefox before 49.0, Firefox ESR 45.x before 45.4, and Thunderbird < 45.4 allows remote attackers to execute arbitrary code via a crafted image data that is mishandled during the encoding of an image frame to an image. | CVSS3: 8.8 | 4% Низкий | почти 10 лет назад |
Уязвимостей на страницу