Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-1957
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firef ...
CVE-2016-1957
Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array.
CVE-2016-1956
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is us ...
CVE-2016-1956
Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader.
CVE-2016-1955
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same ...
CVE-2016-1955
Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element.
CVE-2016-1954
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cp ...
CVE-2016-1954
The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file.
CVE-2016-1953
Multiple unspecified vulnerabilities in the browser engine in Mozilla ...
CVE-2016-1953
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-1957 Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firef ... | CVSS3: 4.3 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1957 Memory leak in libstagefright in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to cause a denial of service (memory consumption) via an MPEG-4 file that triggers a delete operation on an array. | CVSS3: 4.3 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1956 Mozilla Firefox before 45.0 on Linux, when an Intel video driver is us ... | CVSS3: 6.5 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1956 Mozilla Firefox before 45.0 on Linux, when an Intel video driver is used, allows remote attackers to cause a denial of service (memory consumption or stack memory corruption) by triggering use of a WebGL shader. | CVSS3: 6.5 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1955 Mozilla Firefox before 45.0 allows remote attackers to bypass the Same ... | CVSS3: 4.3 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1955 Mozilla Firefox before 45.0 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information by reading a Content Security Policy (CSP) violation report that contains path information associated with an IFRAME element. | CVSS3: 4.3 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1954 The nsCSPContext::SendReports function in dom/security/nsCSPContext.cp ... | CVSS3: 8.8 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1954 The nsCSPContext::SendReports function in dom/security/nsCSPContext.cpp in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 does not prevent use of a non-HTTP report-uri for a Content Security Policy (CSP) violation report, which allows remote attackers to cause a denial of service (data overwrite) or possibly gain privileges by specifying a URL of a local file. | CVSS3: 8.8 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1953 Multiple unspecified vulnerabilities in the browser engine in Mozilla ... | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1953 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 45.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via vectors related to js/src/jit/arm/Assembler-arm.cpp, and unknown other vectors. | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад |
Уязвимостей на страницу