Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-7153
The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
CVE-2016-7152
The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack.
ELSA-2016-1809
ELSA-2016-1809: thunderbird security update (IMPORTANT)
SUSE-SU-2016:2209-1
Security update for libtcnative-1-0
CVE-2016-5268
Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI ...
CVE-2016-5268
Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring.
CVE-2016-5267
Mozilla Firefox before 48.0 on Android allows remote attackers to spoo ...
CVE-2016-5267
Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set.
CVE-2016-5266
Mozilla Firefox before 48.0 does not properly restrict drag-and-drop ( ...
CVE-2016-5266
Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-7153 The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | CVSS3: 5.3 | 14% Средний | почти 10 лет назад | |
CVE-2016-7152 The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party cookies are sent, aka a "HEIST" attack. | CVSS3: 5.3 | 14% Средний | почти 10 лет назад | |
ELSA-2016-1809 ELSA-2016-1809: thunderbird security update (IMPORTANT) | 3% Низкий | почти 10 лет назад | ||
SUSE-SU-2016:2209-1 Security update for libtcnative-1-0 | 100% Критический | почти 10 лет назад | ||
CVE-2016-5268 Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI ... | CVSS3: 4.3 | 1% Низкий | около 10 лет назад | |
CVE-2016-5268 Mozilla Firefox before 48.0 does not properly set the LINKABLE and URI_SAFE_FOR_UNTRUSTED_CONTENT flags of about: URLs that are used for error pages, which makes it easier for remote attackers to conduct spoofing attacks via a crafted URL, as demonstrated by misleading text after an about:neterror?d= substring. | CVSS3: 4.3 | 1% Низкий | около 10 лет назад | |
CVE-2016-5267 Mozilla Firefox before 48.0 on Android allows remote attackers to spoo ... | CVSS3: 5.3 | 1% Низкий | около 10 лет назад | |
CVE-2016-5267 Mozilla Firefox before 48.0 on Android allows remote attackers to spoof the address bar via left-to-right characters in conjunction with a right-to-left character set. | CVSS3: 5.3 | 1% Низкий | около 10 лет назад | |
CVE-2016-5266 Mozilla Firefox before 48.0 does not properly restrict drag-and-drop ( ... | CVSS3: 8.1 | 2% Низкий | около 10 лет назад | |
CVE-2016-5266 Mozilla Firefox before 48.0 does not properly restrict drag-and-drop (aka dataTransfer) actions for file: URIs, which allows user-assisted remote attackers to access local files via a crafted web site. | CVSS3: 8.1 | 2% Низкий | около 10 лет назад |
Уязвимостей на страницу