Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-1977
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 b ...
CVE-2016-1977
The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font.
CVE-2016-1976
Use-after-free vulnerability in the DesktopDisplayDevice class in the ...
CVE-2016-1976
Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
CVE-2016-1975
Multiple race conditions in dom/media/systemservices/CamerasChild.cpp ...
CVE-2016-1975
Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2016-1974
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox befor ...
CVE-2016-1974
The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document.
CVE-2016-1973
Race condition in the GetStaticInstance function in the WebRTC impleme ...
CVE-2016-1973
Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-1977 The Machine::Code::decoder::analysis::set_ref function in Graphite 2 b ... | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1977 The Machine::Code::decoder::analysis::set_ref function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7, allows remote attackers to execute arbitrary code or cause a denial of service (stack memory corruption) via a crafted Graphite smart font. | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1976 Use-after-free vulnerability in the DesktopDisplayDevice class in the ... | CVSS3: 5.5 | 1% Низкий | больше 10 лет назад | |
CVE-2016-1976 Use-after-free vulnerability in the DesktopDisplayDevice class in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | CVSS3: 5.5 | 1% Низкий | больше 10 лет назад | |
CVE-2016-1975 Multiple race conditions in dom/media/systemservices/CamerasChild.cpp ... | CVSS3: 6.3 | 1% Низкий | больше 10 лет назад | |
CVE-2016-1975 Multiple race conditions in dom/media/systemservices/CamerasChild.cpp in the WebRTC implementation in Mozilla Firefox before 45.0 on Windows might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | CVSS3: 6.3 | 1% Низкий | больше 10 лет назад | |
CVE-2016-1974 The nsScannerString::AppendUnicodeTo function in Mozilla Firefox befor ... | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1974 The nsScannerString::AppendUnicodeTo function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not verify that memory allocation succeeds, which allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via crafted Unicode data in an HTML, XML, or SVG document. | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1973 Race condition in the GetStaticInstance function in the WebRTC impleme ... | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1973 Race condition in the GetStaticInstance function in the WebRTC implementation in Mozilla Firefox before 45.0 might allow remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via unspecified vectors. | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад |
Уязвимостей на страницу