Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-1948
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is u ...
CVE-2016-1948
Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream.
CVE-2016-1947
Mozilla Firefox 43.x mishandles attempts to connect to the Application ...
CVE-2016-1947
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
CVE-2016-1946
The MoofParser::Metadata function in binding/MoofParser.cpp in libstag ...
CVE-2016-1946
The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata.
CVE-2016-1945
The nsZipArchive function in Mozilla Firefox before 44.0 might allow r ...
CVE-2016-1945
The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive.
CVE-2016-1944
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozill ...
CVE-2016-1944
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-1948 Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is u ... | CVSS3: 5.3 | 0% Низкий | больше 10 лет назад | |
CVE-2016-1948 Mozilla Firefox before 44.0 on Android does not ensure that HTTPS is used for a lightweight-theme installation, which allows man-in-the-middle attackers to replace a theme's images and colors by modifying the client-server data stream. | CVSS3: 5.3 | 0% Низкий | больше 10 лет назад | |
CVE-2016-1947 Mozilla Firefox 43.x mishandles attempts to connect to the Application ... | CVSS3: 4.7 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1947 Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data. | CVSS3: 4.7 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1946 The MoofParser::Metadata function in binding/MoofParser.cpp in libstag ... | CVSS3: 9.8 | 6% Низкий | больше 10 лет назад | |
CVE-2016-1946 The MoofParser::Metadata function in binding/MoofParser.cpp in libstagefright in Mozilla Firefox before 44.0 does not limit the size of read operations, which might allow remote attackers to cause a denial of service (integer overflow and buffer overflow) or possibly have unspecified other impact via crafted metadata. | CVSS3: 9.8 | 6% Низкий | больше 10 лет назад | |
CVE-2016-1945 The nsZipArchive function in Mozilla Firefox before 44.0 might allow r ... | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1945 The nsZipArchive function in Mozilla Firefox before 44.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by leveraging incorrect use of a pointer during processing of a ZIP archive. | CVSS3: 8.8 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1944 The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozill ... | CVSS3: 9.8 | 4% Низкий | больше 10 лет назад | |
CVE-2016-1944 The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | CVSS3: 9.8 | 4% Низкий | больше 10 лет назад |
Уязвимостей на страницу