Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-1962
Use-after-free vulnerability in the mozilla::DataChannelConnection::Cl ...
CVE-2016-1962
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
CVE-2016-1961
Use-after-free vulnerability in the nsHTMLDocument::SetBody function i ...
CVE-2016-1961
Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574.
CVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string ...
CVE-2016-1960
Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545.
CVE-2016-1959
The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows r ...
CVE-2016-1959
The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API.
CVE-2016-1958
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Fir ...
CVE-2016-1958
browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-1962 Use-after-free vulnerability in the mozilla::DataChannelConnection::Cl ... | CVSS3: 9.8 | 6% Низкий | больше 10 лет назад | |
CVE-2016-1962 Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections. | CVSS3: 9.8 | 6% Низкий | больше 10 лет назад | |
CVE-2016-1961 Use-after-free vulnerability in the nsHTMLDocument::SetBody function i ... | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1961 Use-after-free vulnerability in the nsHTMLDocument::SetBody function in dom/html/nsHTMLDocument.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of a root element, aka ZDI-CAN-3574. | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1960 Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string ... | CVSS3: 8.8 | 31% Средний | больше 10 лет назад | |
CVE-2016-1960 Integer underflow in the nsHtml5TreeBuilder class in the HTML5 string parser in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) by leveraging mishandling of end tags, as demonstrated by incorrect SVG processing, aka ZDI-CAN-3545. | CVSS3: 8.8 | 31% Средний | больше 10 лет назад | |
CVE-2016-1959 The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows r ... | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1959 The ServiceWorkerManager class in Mozilla Firefox before 45.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read and memory corruption) via unspecified use of the Clients API. | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1958 browser/base/content/browser.js in Mozilla Firefox before 45.0 and Fir ... | CVSS3: 4.3 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1958 browser/base/content/browser.js in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to spoof the address bar via a javascript: URL. | CVSS3: 4.3 | 2% Низкий | больше 10 лет назад |
Уязвимостей на страницу