Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-2838
Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document.
ELSA-2016-1392
ELSA-2016-1392: thunderbird security update (IMPORTANT)
SUSE-SU-2016:1618-1
Security update for mysql
CVE-2016-2834
Mozilla Network Security Services (NSS) before 3.23, as used in Mozill ...
CVE-2016-2834
Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors.
CVE-2016-2833
Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) dire ...
CVE-2016-2833
Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet.
CVE-2016-2832
Mozilla Firefox before 47.0 allows remote attackers to discover the li ...
CVE-2016-2832
Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes.
CVE-2016-2831
Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not en ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-2838 Heap-based buffer overflow in the nsBidi::BracketData::AddOpening function in Mozilla Firefox before 48.0 and Firefox ESR 45.x before 45.3 allows remote attackers to execute arbitrary code via directional content in an SVG document. | CVSS3: 8.8 | 5% Низкий | около 10 лет назад | |
ELSA-2016-1392 ELSA-2016-1392: thunderbird security update (IMPORTANT) | 4% Низкий | около 10 лет назад | ||
SUSE-SU-2016:1618-1 Security update for mysql | 100% Критический | около 10 лет назад | ||
CVE-2016-2834 Mozilla Network Security Services (NSS) before 3.23, as used in Mozill ... | CVSS3: 8.8 | 3% Низкий | около 10 лет назад | |
CVE-2016-2834 Mozilla Network Security Services (NSS) before 3.23, as used in Mozilla Firefox before 47.0, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via unknown vectors. | CVSS3: 8.8 | 3% Низкий | около 10 лет назад | |
CVE-2016-2833 Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) dire ... | CVSS3: 6.1 | 1% Низкий | около 10 лет назад | |
CVE-2016-2833 Mozilla Firefox before 47.0 ignores Content Security Policy (CSP) directives for cross-domain Java applets, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted applet. | CVSS3: 6.1 | 1% Низкий | около 10 лет назад | |
CVE-2016-2832 Mozilla Firefox before 47.0 allows remote attackers to discover the li ... | CVSS3: 4.3 | 1% Низкий | около 10 лет назад | |
CVE-2016-2832 Mozilla Firefox before 47.0 allows remote attackers to discover the list of disabled plugins via a fingerprinting attack involving Cascading Style Sheets (CSS) pseudo-classes. | CVSS3: 4.3 | 1% Низкий | около 10 лет назад | |
CVE-2016-2831 Mozilla Firefox before 47.0 and Firefox ESR 45.x before 45.2 do not en ... | CVSS3: 8.8 | 1% Низкий | около 10 лет назад |
Уязвимостей на страницу