Mozilla Firefox — свободный браузер на движке Gecko
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 138.0.4 | 138.0.4 | ||
| 138.0.3 | 138.0.3 | ||
| 138.0.1 | 138.0.1 | ||
| 138.0 | 138.0 |
Показывать по
Количество 17 337
CVE-2016-1938
The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function.
CVE-2016-1947
Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data.
CVE-2016-1944
The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
CVE-2016-1943
Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method.
CVE-2016-1935
Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content.
SUSE-SU-2016:0189-1
Security update for mozilla-nss
openSUSE-SU-2016:0162-1
Security update for mbedtls
SUSE-SU-2016:0149-1
Security update for mozilla-nss
CVE-2015-7575
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozi ...
CVE-2015-7575
Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2016-1938 The s_mp_div function in lib/freebl/mpi/mpi.c in Mozilla Network Security Services (NSS) before 3.21, as used in Mozilla Firefox before 44.0, improperly divides numbers, which might make it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging use of the (1) mp_div or (2) mp_exptmod function. | CVSS2: 2.6 | 3% Низкий | больше 10 лет назад | |
CVE-2016-1947 Mozilla Firefox 43.x mishandles attempts to connect to the Application Reputation service, which makes it easier for remote attackers to trigger an unintended download by leveraging the absence of reputation data. | CVSS2: 4.3 | 2% Низкий | больше 10 лет назад | |
CVE-2016-1944 The Buffer11::NativeBuffer11::map function in ANGLE, as used in Mozilla Firefox before 44.0, might allow remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | CVSS2: 6.8 | 4% Низкий | больше 10 лет назад | |
CVE-2016-1943 Mozilla Firefox before 44.0 on Android allows remote attackers to spoof the address bar via the scrollTo method. | CVSS2: 4.3 | 1% Низкий | больше 10 лет назад | |
CVE-2016-1935 Buffer overflow in the BufferSubData function in Mozilla Firefox before 44.0 and Firefox ESR 38.x before 38.6 allows remote attackers to execute arbitrary code via crafted WebGL content. | CVSS2: 6.8 | 5% Низкий | больше 10 лет назад | |
SUSE-SU-2016:0189-1 Security update for mozilla-nss | 3% Низкий | больше 10 лет назад | ||
openSUSE-SU-2016:0162-1 Security update for mbedtls | 3% Низкий | больше 10 лет назад | ||
SUSE-SU-2016:0149-1 Security update for mozilla-nss | 3% Низкий | больше 10 лет назад | ||
CVE-2015-7575 Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozi ... | CVSS3: 5.9 | 3% Низкий | больше 10 лет назад | |
CVE-2015-7575 Mozilla Network Security Services (NSS) before 3.20.2, as used in Mozilla Firefox before 43.0.2 and Firefox ESR 38.x before 38.5.2, does not reject MD5 signatures in Server Key Exchange messages in TLS 1.2 Handshake Protocol traffic, which makes it easier for man-in-the-middle attackers to spoof servers by triggering a collision. | CVSS3: 5.9 | 3% Низкий | больше 10 лет назад |
Уязвимостей на страницу