Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-1962
Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections.
CVE-2016-1969
The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font.
openSUSE-SU-2016:0605-1
Security update for bouncycastle
SUSE-SU-2016:0564-1
Security update for MozillaFirefox
SUSE-SU-2016:0554-1
Security update for MozillaFirefox
openSUSE-SU-2016:0489-1
Security update for MozillaFirefox
openSUSE-SU-2016:0478-1
Security update for socat
CVE-2016-1949
Mozilla Firefox before 44.0.2 does not properly restrict the interacti ...
CVE-2016-1949
Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file.
CVE-2016-1526
The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graph ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-1962 Use-after-free vulnerability in the mozilla::DataChannelConnection::Close function in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.7 allows remote attackers to execute arbitrary code by leveraging mishandling of WebRTC data-channel connections. | CVSS2: 6.8 | 6% Низкий | больше 10 лет назад | |
CVE-2016-1969 The setAttr function in Graphite 2 before 1.3.6, as used in Mozilla Firefox before 45.0 and Firefox ESR 38.x before 38.6.1, allows remote attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact via a crafted Graphite smart font. | CVSS2: 4.3 | 2% Низкий | больше 10 лет назад | |
openSUSE-SU-2016:0605-1 Security update for bouncycastle | 3% Низкий | больше 10 лет назад | ||
SUSE-SU-2016:0564-1 Security update for MozillaFirefox | 2% Низкий | больше 10 лет назад | ||
SUSE-SU-2016:0554-1 Security update for MozillaFirefox | 2% Низкий | больше 10 лет назад | ||
openSUSE-SU-2016:0489-1 Security update for MozillaFirefox | 2% Низкий | больше 10 лет назад | ||
openSUSE-SU-2016:0478-1 Security update for socat | 100% Критический | больше 10 лет назад | ||
CVE-2016-1949 Mozilla Firefox before 44.0.2 does not properly restrict the interacti ... | CVSS3: 8.8 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1949 Mozilla Firefox before 44.0.2 does not properly restrict the interaction between Service Workers and plugins, which allows remote attackers to bypass the Same Origin Policy via a crafted web site that triggers spoofed responses to requests that use NPAPI, as demonstrated by a request for a crossdomain.xml file. | CVSS3: 8.8 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1526 The TtfUtil:LocaLookup function in TtfUtil.cpp in Libgraphite in Graph ... | CVSS3: 8.1 | 2% Низкий | больше 10 лет назад |
Уязвимостей на страницу