Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-5260
Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="passw ...
CVE-2016-5260
Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file.
CVE-2016-5259
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant funct ...
CVE-2016-5259
Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop.
CVE-2016-5258
Use-after-free vulnerability in the WebRTC socket thread in Mozilla Fi ...
CVE-2016-5258
Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session.
CVE-2016-5255
Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep ...
CVE-2016-5255
Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection.
CVE-2016-5254
Use-after-free vulnerability in the nsXULPopupManager::KeyDown functio ...
CVE-2016-5254
Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) by leveraging keyboard access to use the Alt key during selection of top-level menu items.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-5260 Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="passw ... | CVSS3: 6.5 | 1% Низкий | около 10 лет назад | |
CVE-2016-5260 Mozilla Firefox before 48.0 mishandles changes from 'INPUT type="password"' to 'INPUT type="text"' within a single Session Manager session, which might allow attackers to discover cleartext passwords by reading a session restoration file. | CVSS3: 6.5 | 1% Низкий | около 10 лет назад | |
CVE-2016-5259 Use-after-free vulnerability in the CanonicalizeXPCOMParticipant funct ... | CVSS3: 8.8 | 3% Низкий | около 10 лет назад | |
CVE-2016-5259 Use-after-free vulnerability in the CanonicalizeXPCOMParticipant function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via a script that closes its own Service Worker within a nested sync event loop. | CVSS3: 8.8 | 3% Низкий | около 10 лет назад | |
CVE-2016-5258 Use-after-free vulnerability in the WebRTC socket thread in Mozilla Fi ... | CVSS3: 8.8 | 3% Низкий | около 10 лет назад | |
CVE-2016-5258 Use-after-free vulnerability in the WebRTC socket thread in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code by leveraging incorrect free operations on DTLS objects during the shutdown of a WebRTC session. | CVSS3: 8.8 | 3% Низкий | около 10 лет назад | |
CVE-2016-5255 Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep ... | CVSS3: 8.8 | 2% Низкий | около 10 лет назад | |
CVE-2016-5255 Use-after-free vulnerability in the js::PreliminaryObjectArray::sweep function in Mozilla Firefox before 48.0 allows remote attackers to execute arbitrary code via crafted JavaScript that is mishandled during incremental garbage collection. | CVSS3: 8.8 | 2% Низкий | около 10 лет назад | |
CVE-2016-5254 Use-after-free vulnerability in the nsXULPopupManager::KeyDown functio ... | CVSS3: 9.8 | 3% Низкий | около 10 лет назад | |
CVE-2016-5254 Use-after-free vulnerability in the nsXULPopupManager::KeyDown function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows attackers to execute arbitrary code or cause a denial of service (heap memory corruption and application crash) by leveraging keyboard access to use the Alt key during selection of top-level menu items. | CVSS3: 9.8 | 3% Низкий | около 10 лет назад |
Уязвимостей на страницу